PT-2026-73220 · Assimp · Assimp

·

CVE-2026-19999

·

Published

2026-08-17

·

Updated

2026-08-17

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Open Asset Import Library Assimp version 17c12da
Description A buffer overflow can be triggered remotely via the manipulation of the transmatrix count/pcBoneTransforms argument within the Assimp::MDLImporter::ParseBoneTrafoKeys 3DGS MDL7() function, located in the 3DGS MDL7 Bone Transformation Key Parser component.
Recommendations Apply patch 50d767984e78d51b53e2020fdf0967fd624bc377 to version 17c12da.

Exploit

Fix

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-19999

Affected Products

Assimp