CVE-2026-10233
3.3 LOWA security vulnerability has been detected in Assimp up to 6.0.4
Published: 2026-06-01 · Last updated: 2026-06-03
Severity and scoring
- CVSS
- 3.3 LOW
- Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
- CWE
- CWE-119, CWE-125
Description
A security vulnerability has been detected in Assimp up to 6.0.4. Affected by this issue is the function HL1MDLLoader::read_sequence_infos of the file HL1MDLLoader.cpp of the component Half-Life 1 MDL Loader. The manipulation of the argument aiString leads to out-of-bounds read. The attack needs to be performed locally. The exploit has been disclosed publicly and may be used. The project tagged the reported issue as bug.
Source: NVD
References
- [NVD]https://nvd.nist.gov/vuln/detail/CVE-2026-10233
- [Other]https://github.com/assimp/assimp/
- [Other]https://github.com/assimp/assimp/issues/6619
- [Other]https://github.com/user-attachments/files/27228962/poc.zip
- [Other]https://vuldb.com/cve/CVE-2026-10233
- [Other]https://vuldb.com/submit/821196
- [Other]https://vuldb.com/vuln/367512
- [Other]https://vuldb.com/vuln/367512/cti
- [Other]https://github.com/assimp/assimp/issues/6619
Related CVEs
Same CWE
- CVE-2026-47166 — ImageMagick is free and open-source software used for editing and manipulating digital images (5.7 MEDIUM)
- CVE-2026-45624 — ImageMagick is free and open-source software used for editing and manipulating digital images (5.1 MEDIUM)
- CVE-2026-45359 — ImageMagick is free and open-source software used for editing and manipulating digital images (5.7 MEDIUM)
- CVE-2026-45358 — ImageMagick is free and open-source software used for editing and manipulating digital images (5.3 MEDIUM)
- CVE-2026-42326 — ImageMagick is free and open-source software used for editing and manipulating digital images (5.1 MEDIUM)