GHSA-797q-3h4c-269wLowCVSS 5.3
A vulnerability was determined in Assimp up to 6.0.4. This affects the function HL1MDLLoader:...
🔗 CVE IDs covered (1)
📋 Description
A vulnerability was determined in Assimp up to 6.0.4. This affects the function HL1MDLLoader::read_meshes of the file HL1MDLLoader.cpp of the component Half-Life 1 MDL Loader. This manipulation causes heap-based buffer overflow. The attack is restricted to local execution. The exploit has been publicly disclosed and may be utilized. The project tagged the reported issue as bug.
🔗 References (9)
- https://nvd.nist.gov/vuln/detail/CVE-2026-10229
- https://github.com/assimp/assimp/issues/6614
- https://github.com/assimp/assimp
- https://github.com/user-attachments/files/27194364/poc.zip
- https://vuldb.com/cve/CVE-2026-10229
- https://vuldb.com/submit/821189
- https://vuldb.com/vuln/367508
- https://vuldb.com/vuln/367508/cti
- https://github.com/advisories/GHSA-797q-3h4c-269w