
🐍 CVE-2026-29075 (Mesa <=3.5.0 Python agent modeling): Critical RCE in benchmarks.yml GitHub workflow via untrusted code checkout. Patch: c35b8cd+ https://github.com/projectmesa/mesa/security/advisories/GHSA-3j55-5q6x-2h48 https://nvd.nist.gov/vuln/detail/CVE-2026-29075 https://github.com/projectmesa/mesa/security/advisories/GHSA-3j55-5q6x-2h48
Post summary
Mesa version ≤3.5.0 has a critical RCE in its GitHub workflow (CVE‑2026‑29075), and a patch (commit c35b8cd+) is available via the official advisory.



