Assimp · Assimp · CVE-2026-82591
**Name of the Vulnerable Software and Affected Versions**
Open Asset Import Library Assimp versions prior to 6.0.3
**Description**
A heap-based buffer overflow occurs when manipulating the `iNewIndex` argument within the `MD5Importer::MakeDataUnique()` function located in the code/AssetLib/MD5/MD5Loader.cpp file. This issue can be exploited from a local environment.
**Recommendations**
Apply the patch identified as bf9dabb617c46e5133dac65cca6bff177917afcb to resolve the issue.