CVE-2026-10233

A security vulnerability has been detected in Assimp up to 6.0.4. Affected by this issue is the function HL1MDLLoader::read_sequence_infos of the file HL1MDLLoader.cpp of the component Half-Life 1 MDL Loader. The manipulation of the argument aiString leads to out-of-bounds read. The attack needs to be performed locally. The exploit has been disclosed publicly and may be used. The project tagged the reported issue as bug.
Configurations

No configuration.

History

03 Jun 2026, 19:16

Type Values Removed Values Added
References () https://github.com/assimp/assimp/issues/6619 - () https://github.com/assimp/assimp/issues/6619 -

01 Jun 2026, 08:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-06-01 08:16

Updated : 2026-06-03 19:16


NVD link : CVE-2026-10233

Mitre link : CVE-2026-10233

CVE.ORG link : CVE-2026-10233


JSON object : View

Products Affected

No product.

CWE
CWE-119

Improper Restriction of Operations within the Bounds of a Memory Buffer

CWE-125

Out-of-bounds Read