


Perceptive Security
SOC/SIEM Consultancy

Mesa is an open-source Python library for agent-based modeling, simulating complex systems and exploring emergent behaviors. In version 3.5.0 and prior, checkin…
Published:
5 maart 2026 om 23:00:00
Alert date:
6 maart 2026 om 18:01:51
Source:
nvd.nist.gov
Supply Chain & Dependencies
CVE-2026-29075 affects Mesa, an open-source Python library for agent-based modeling. The vulnerability exists in version 3.5.0 and prior, where untrusted code checkout in the benchmarks.yml workflow can lead to code execution in privileged runners. This represents a supply chain attack vector through CI/CD pipeline exploitation. The issue has been patched via commit c35b8cd. The vulnerability allows attackers to potentially execute malicious code within the project's automated testing environment.
Technical details
Mitigation steps:
Affected products:
Mesa Python Library
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-29075
https://github.com/mesa/mesa/commit/c35b8cd67fc89dd680ae218e49b77f6e1ee07a27
https://github.com/mesa/mesa/security/advisories/GHSA-3j55-5q6x-2h48
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
