Mesa · Mesa · CVE-2026-29075
**Name of the Vulnerable Software and Affected Versions**
Mesa versions prior to 3.5.1
**Description**
Mesa is a Python library used for agent-based modeling and simulating complex systems. A flaw exists where checking out untrusted code within the benchmarks.yml workflow could allow for code execution with elevated privileges on the runner system. This issue was addressed with commit c35b8cd.
**Recommendations**
Update to Mesa version 3.5.1 or later.