Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2024-29189

23
FAUCET Score

CVE-2024-29189 is a high-severity vulnerability (CVSS 7.8) affecting PyAnsys Geometry, a Python client library for Ansys Geometry and other CAD products. The vulnerability, categorized as CWE-78 (Improper Neutralization of Special Elements used in an OS Command), allows authenticated local attackers to execute arbitrary commands on the system where the script is run by exploiting the _start_program method. This could lead to complete compromise of confidentiality, integrity, and availability. While there is no evidence of active exploitation, public exploit code, or significant community discussion, the vulnerability has been patched in versions 0.3.3 and 0.4.12.

Impacted Technologies

VendorProductVersion(s)CPE
>= 0.3.0, < 0.3.3CPE matchmatch criteria
cpe:2.3:a:ansys:pyansys_geometry:*:*:*:*:*:*:*:*
>= 0.4.0, < 0.4.12CPE matchmatch criteria
cpe:2.3:a:ansys:pyansys_geometry:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

7.4HIGH

CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Attack Vector
LOCAL
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
1.4
Impact Score
5.9
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.33%
Probability of exploitation in next 30 days
EPSS Percentile
25.8%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0033 is in the 64th percentile among its peer group of 17,070 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (3)

github_advisorypatch availablevia nvd_reference
View patch
pippatch availablevia ghsa
Product: ansys-geometry-coreFixed in: 0.3.3
pippatch availablevia ghsa
Product: ansys-geometry-coreFixed in: 0.4.12

Vendor Advisories (1)

pipGHSA-38jr-29fh-w9vmhigh

ansys-geometry-core OS Command Injection vulnerability

Mar 25, 2024

References

bandit.readthedocs.io / en/1.7.8/plugins/b602_subprocess_popen_with_shell_equals_true.html
Technical Description
github.com / ansys/pyansys-geometry/blob/52cba1737a8a7812e5430099f715fa2160ec007b/src/ansys/geometry/core/connection/product_instance.py
Patch
github.com / ansys/pyansys-geometry/commit/902071701c4f3a8258cbaa46c28dc0a65442d1bc
Patch
github.com / ansys/pyansys-geometry/commit/f82346b9432b06532e84f3278125f5879b4e9f3f
Patch
github.com / ansys/pyansys-geometry/pull/1076
Issue Tracking
github.com / ansys/pyansys-geometry/pull/1077
Issue Tracking
github.com / ansys/pyansys-geometry/security/advisories/GHSA-38jr-29fh-w9vm
ExploitVendor Advisory