CVE-2026-10231
5.3 MEDIUMA security flaw has been discovered in Assimp up to 6.0.4
Published: 2026-06-01 · Last updated: 2026-06-01
Severity and scoring
- CVSS
- 5.3 MEDIUM
- Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
- CWE
- CWE-119, CWE-122
Description
A security flaw has been discovered in Assimp up to 6.0.4. Affected is the function HL1MDLLoader::extract_anim_value of the file HL1MDLLoader.cpp of the component Half-Life 1 MDL Loader. Performing a manipulation of the argument num.total results in heap-based buffer overflow. The attack must be initiated from a local position. The exploit has been released to the public and may be used for attacks. The project tagged the reported issue as bug.
Source: NVD
References
- [NVD]https://nvd.nist.gov/vuln/detail/CVE-2026-10231
- [Other]https://github.com/assimp/assimp/
- [Other]https://github.com/assimp/assimp/issues/6616
- [Other]https://github.com/user-attachments/files/27195744/poc.zip
- [Other]https://vuldb.com/cve/CVE-2026-10231
- [Other]https://vuldb.com/submit/821191
- [Other]https://vuldb.com/vuln/367510
- [Other]https://vuldb.com/vuln/367510/cti
Related CVEs
Same CWE
- CVE-2026-12216 — A weakness has been identified in svaarala duktape up to 2.99.99 (5.3 MEDIUM)
- CVE-2026-12200 — A security vulnerability has been detected in Ritlabs TinyWeb Server up to 1.94 on Win32 (7.3 HIGH)
- CVE-2026-12193 — A vulnerability was identified in VS Revo RevoUninstaller 2.5.x/2.6.x (7.8 HIGH)
- CVE-2026-12192 — A vulnerability was determined in GALAYOU Y4 1.0.0 (8.8 HIGH)
- CVE-2026-12174 — A security vulnerability has been detected in D-Link DCS-935L 1.10.01 (8.8 HIGH)