Blender 2.34, 2.35a, 2.40, and 2.49b allows remote attackers to execute arbitrary code via a .blend file that contains Python statements in the onLoad action of a ScriptLink SDNA.
{ "urgency": "unimportant" }
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2009-3850.json"