Heap-based Buffer Overflow in Assimp Library - Vulnerability Analysis
CVE-2026-10200

4.8MEDIUM

Key Information:

Vendor

Assimp

Status
Vendor
CVE Published:
31 May 2026

Badges

👾 Exploit Exists🟡 Public PoC

What is CVE-2026-10200?

A heap-based buffer overflow vulnerability in the Assimp library up to version 6.0.4 has been identified, specifically affecting the function glTFCommon::CopyValue within glTFCommon.h. This vulnerability allows an attacker to perform local exploits that could potentially lead to arbitrary code execution or the corruption of memory. Given that the exploit has been publicly shared, it is essential for users of the affected versions to apply necessary mitigations immediately to secure their systems. The issue has been documented and tracked in the project’s issue tracker, flagged as a bug.

Affected Version(s)

Assimp 6.0.0

Assimp 6.0.1

Assimp 6.0.2

Exploit Proof of Concept (PoC)

PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.

References

CVSS V4

Score:
4.8
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • 🟡

    Public PoC available

  • 👾

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

Credit

TYGLS (VulDB User)
VulDB CNA Team
.