4.8
/ 10
MEDIUM
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P
Description
A vulnerability was identified in Assimp up to 6.0.4. This impacts the function Assimp::MDL::HalfLife::HL1MDLLoader::read_animations of the file HL1MDLLoader.cpp of the component Half-Life 1 MDL Loader. Such manipulation leads to heap-based buffer overflow. The attack must be carried out locally. The exploit is publicly available and might be used. The project tagged the reported issue as bug.
Basic Information
ID
CVE-2026-10230
Source
VulDB
Published
Jun 1, 2026 at 06:00
Affected Product
Vendor
n/a
Product
Assimp
Version
6.0.0
Affected Versions
n/a Assimp 6.0.0
n/a Assimp 6.0.1
n/a Assimp 6.0.2
n/a Assimp 6.0.3
n/a Assimp 6.0.4
n/a Assimp 6.0.1
n/a Assimp 6.0.2
n/a Assimp 6.0.3
n/a Assimp 6.0.4