Heap-based Buffer Overflow in Open Asset Import Library Assimp Affects 3DGS MDL7 Model Parser
CVE-2026-19968
Key Information:
- Vendor
Open Asset Import Library
- Status
- Vendor
- CVE Published:
- 17 August 2026
Badges
What is CVE-2026-19968?
A weakness exists within the Open Asset Import Library Assimp specifically related to the function Assimp::MDLImporter::ReadFaces_3DGS_MDL7. This vulnerability can potentially lead to a heap-based buffer overflow, allowing attackers to execute malicious code. The exploit can be initiated remotely, raising significant security concerns. A patch has been released to address this issue, and it is strongly recommended to apply the available fix to enhance security integrity.
Affected Version(s)
Assimp 17c12da
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
