Heap-based Buffer Overflow in Assimp Library - Vulnerability Analysis
CVE-2026-10200
Key Information:
Badges
What is CVE-2026-10200?
A heap-based buffer overflow vulnerability in the Assimp library up to version 6.0.4 has been identified, specifically affecting the function glTFCommon::CopyValue within glTFCommon.h. This vulnerability allows an attacker to perform local exploits that could potentially lead to arbitrary code execution or the corruption of memory. Given that the exploit has been publicly shared, it is essential for users of the affected versions to apply necessary mitigations immediately to secure their systems. The issue has been documented and tracked in the project’s issue tracker, flagged as a bug.
Affected Version(s)
Assimp 6.0.0
Assimp 6.0.1
Assimp 6.0.2
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved
