Blender 2.34, 2.35a, 2.40, and 2.49b allows remote attackers to execute arbitrary code via a .blend file that contains Python statements in the onLoad action of a ScriptLink SDNA.
http://www.securityfocus.com/bid/36838
http://www.securityfocus.com/archive/1/507706/100/0/threaded