CVE-2026-29075Disclosure(mesa_project / mesa)

LOWCVSS 9.8 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch mesa_project mesa systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Mesa is an open-source Python library for agent-based modeling, simulating complex systems and exploring emergent behaviors. In version 3.5.0 and prior, checking out of untrusted code in benchmarks.yml workflow may lead to code execution in privileged runner. This issue has been patched via commit c35b8cd.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-94

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • mesa

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • Peaked 2d ago at 2 mentions (2026-03-06); latest day: 1
  • 4 total mentions across 3 days

Affected systems

Products
mesa

Deep dive

Activity timeline4 mentions / 3d
01122Mentions · 2026-03-06: 2Mentions · 2026-03-07: 1Mentions · 2026-03-29: 1Patch / Workaround · 2026-03-29: 1Technical Details · 2026-03-06: 1Technical Details · 2026-03-29: 103-0603-0703-29
Signal classification3 categories
Disclosure
250.0%
General
125.0%
Patch
125.0%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-03-062
Disclosure1General1
2026-03-071
Disclosure1
2026-03-291
Patch1
Full discourse4 posts
  • White Rabbitx@TheRabbitPy
    Patch

    🐍 CVE-2026-29075 (Mesa <=3.5.0 Python agent modeling): Critical RCE in benchmarks.yml GitHub workflow via untrusted code checkout. Patch: c35b8cd+ https://github.com/projectmesa/mesa/security/advisories/GHSA-3j55-5q6x-2h48 https://nvd.nist.gov/vuln/detail/CVE-2026-29075 https://github.com/projectmesa/mesa/security/advisories/GHSA-3j55-5q6x-2h48

    Post summary

    Mesa version ≤3.5.0 has a critical RCE in its GitHub workflow (CVE‑2026‑29075), and a patch (commit c35b8cd+) is available via the official advisory.

    1000051
    492 followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🟠 CVE-2026-29075 - High Mesa is an open-source Python library for agent-based modeling, simulating complex systems and exploring emergent behaviors. In version 3.5.0 and prior, checking out of untrusted code in benc... https://www.thehackerwire.com/vulnerability/CVE-2026-29075/ https://t.co/yVRH12UPen

    Post summary

    The post announces a new high-severity CVE-2026-29075 in the Mesa Python library but provides no further details or actionable information.

    0000034
    128 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-29075 Code Execution Vulnerability in Mesa Python Library Workflow Prio... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-29075 Vulnerability Alert Subscriptions: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=1

    Post summary

    Short tweet announces CVE‑2026‑29075, a code execution flaw in the Mesa Python Library, linking to a Vulmon vulnerability detail page.

    0000038
    4.0K followersView on X
  • CVE@CVEnew
    General

    CVE-2026-29075 Mesa is an open-source Python library for agent-based modeling, simulating complex systems and exploring emergent behaviors. In version 3.5.0 and prior, checking out … https://www.cve.org/CVERecord?id=CVE-2026-29075

    Post summary

    The statement references a CVE for the Mesa library but provides virtually no technical or actionable information.

    0000079
    56.6K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appmesa_projectmesa-python-

Explore more