CVE-2026-10201
3.3 LOWA vulnerability was determined in Assimp up to 6.0.4
Published: 2026-06-01 · Last updated: 2026-06-01
Severity and scoring
- CVSS
- 3.3 LOW
- Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
- CWE
- CWE-369, CWE-404
Description
A vulnerability was determined in Assimp up to 6.0.4. This vulnerability affects the function FBXExporter::WriteObjects of the file FBXExporter.cpp of the component UV Channel Handler. Executing a manipulation can lead to divide by zero. The attack needs to be launched locally. The exploit has been publicly disclosed and may be utilized. Applying a patch is advised to resolve this issue. The project tagged the reported issue as bug.
Source: NVD
References
- [NVD]https://nvd.nist.gov/vuln/detail/CVE-2026-10201
- [Other]https://github.com/assimp/assimp/
- [Other]https://github.com/assimp/assimp/issues/6613
- [Other]https://github.com/user-attachments/files/27153727/poc.zip
- [Other]https://vuldb.com/cve/CVE-2026-10201
- [Other]https://vuldb.com/submit/821182
- [Other]https://vuldb.com/vuln/367481
- [Other]https://vuldb.com/vuln/367481/cti
Related CVEs
Same CWE
- CVE-2026-47213 — Boxlite is a sandbox service that allows users to create lightweight virtual machines (Boxes) and launch OCI containers within them to ru... (6.5 MEDIUM)
- CVE-2026-11312 — A vulnerability was found in bytedance InfiniStore up to 0.2.33 (3.3 LOW)
- CVE-2026-10802 — A vulnerability was detected in keystonejs keystone up to 20260319 (4.3 MEDIUM)
- CVE-2026-10775 — A vulnerability was determined in sgl-project SGLang up to 0.5.11 (3.6 LOW)
- CVE-2025-70100 — A divide-by-zero vulnerability in the ext4_block_set_lb_size function in src/ext4_blockdev.c of the lwext4 1.0.0 library allows attackers... (5.5 MEDIUM)