pyassimp
Python bindings for the Open Asset Import Library (ASSIMP)
Activity
- Latest release
- 3y ago
- Total releases
- 7
- Cadence
- ~10 months
- Last 12 months
- 0
Details
- License
- ISC
- First release
- Jan 04, 2016
| Version | Released | |
|---|---|---|
5.2.5
major
33 CVEs
CVE-2025-11277
PYSEC-2025-157
Oct 05, 2025
7.8
/ 10
High
Local
Low
Low
None
Unchanged
High
High
High
A weakness has been identified in Open Asset Import Library Assimp 6.0.2. This affects the function Q3DImporter::InternReadFile of the file assimp/code/AssetLib/Q3D/Q3DLoader.cpp. Executing a manipulation can lead to heap-based buffer overflow. The attack needs to be launched locally. The exploit has been made available to the public and could be used for attacks. Affected versions
0.1
3.3
4.1.1
4.1.2
4.1.3
4.1.4
5.2.5
References Updated May 21, 2026 · Source: OSV.dev
CVE-2025-11275
PYSEC-2025-156
Oct 05, 2025
7.8
/ 10
High
Local
Low
Low
None
Unchanged
High
High
High
A vulnerability was identified in Open Asset Import Library Assimp 6.0.2. Affected by this vulnerability is the function ODDLParser::getNextSeparator in the library assimp/contrib/openddlparser/include/openddlparser/OpenDDLParserUtils.h. Such manipulation leads to heap-based buffer overflow. The attack must be carried out locally. The exploit is publicly available and might be used. Affected versions
0.1
3.3
4.1.1
4.1.2
4.1.3
4.1.4
5.2.5
References Updated May 21, 2026 · Source: OSV.dev
CVE-2025-11274
PYSEC-2025-155
Oct 05, 2025
5.5
/ 10
Medium
Local
Low
Low
None
Unchanged
None
None
High
A vulnerability was determined in Open Asset Import Library Assimp 6.0.2. Affected is the function Q3DImporter::InternReadFile of the file assimp/code/AssetLib/Q3D/Q3DLoader.cpp. This manipulation causes allocation of resources. The attack is restricted to local execution. The exploit has been publicly disclosed and may be utilized. Affected versions
0.1
3.3
4.1.1
4.1.2
4.1.3
4.1.4
5.2.5
References Updated May 21, 2026 · Source: OSV.dev
CVE-2025-5169
PYSEC-2025-176
May 26, 2025
5.5
/ 10
Medium
Local
Low
Low
None
Unchanged
None
None
High
A vulnerability classified as problematic has been found in Open Asset Import Library Assimp 5.4.3. This affects the function MDLImporter::InternReadFile_3DGS_MDL345 of the file assimp/code/AssetLib/MDL/MDLLoader.cpp. The manipulation leads to out-of-bounds read. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used. The project decided to collect all Fuzzer bugs in a main-issue to address them in the future. Affected versions
0.1
3.3
4.1.1
4.1.2
4.1.3
4.1.4
5.2.5
References Updated May 21, 2026 · Source: OSV.dev
CVE-2025-5168
PYSEC-2025-175
May 26, 2025
5.5
/ 10
Medium
Local
Low
Low
None
Unchanged
None
None
High
A vulnerability was found in Open Asset Import Library Assimp 5.4.3. It has been rated as problematic. Affected by this issue is the function MDLImporter::ImportUVCoordinate_3DGS_MDL345 of the file assimp/code/AssetLib/MDL/MDLLoader.cpp. The manipulation of the argument iIndex leads to out-of-bounds read. An attack has to be approached locally. The exploit has been disclosed to the public and may be used. The project decided to collect all Fuzzer bugs in a main-issue to address them in the future. Affected versions
0.1
3.3
4.1.1
4.1.2
4.1.3
4.1.4
5.2.5
References Updated May 21, 2026 · Source: OSV.dev
CVE-2025-5167
PYSEC-2025-174
May 26, 2025
5.5
/ 10
Medium
Local
Low
Low
None
Unchanged
None
None
High
A vulnerability was found in Open Asset Import Library Assimp 5.4.3. It has been declared as problematic. Affected by this vulnerability is the function LWOImporter::GetS0 in the library assimp/code/AssetLib/LWO/LWOLoader.h. The manipulation of the argument out leads to out-of-bounds read. The attack needs to be approached locally. The exploit has been disclosed to the public and may be used. The project decided to collect all Fuzzer bugs in a main-issue to address them in the future. Affected versions
0.1
3.3
4.1.1
4.1.2
4.1.3
4.1.4
5.2.5
References Updated May 21, 2026 · Source: OSV.dev
CVE-2025-5166
PYSEC-2025-173
May 26, 2025
5.5
/ 10
Medium
Local
Low
Low
None
Unchanged
None
None
High
A vulnerability was found in Open Asset Import Library Assimp 5.4.3. It has been classified as problematic. Affected is the function MDCImporter::InternReadFile of the file assimp/code/AssetLib/MDC/MDCLoader.cpp of the component MDC File Parser. The manipulation of the argument pcVerts leads to out-of-bounds read. It is possible to launch the attack on the local host. The exploit has been disclosed to the public and may be used. The project decided to collect all Fuzzer bugs in a main-issue to address them in the future. Affected versions
0.1
3.3
4.1.1
4.1.2
4.1.3
4.1.4
5.2.5
References Updated May 21, 2026 · Source: OSV.dev
CVE-2025-5165
PYSEC-2025-172
May 26, 2025
5.5
/ 10
Medium
Local
Low
Low
None
Unchanged
None
None
High
A vulnerability was found in Open Asset Import Library Assimp 5.4.3 and classified as problematic. This issue affects the function MDCImporter::ValidateSurfaceHeader of the file assimp/code/AssetLib/MDC/MDCLoader.cpp. The manipulation of the argument pcSurface2 leads to out-of-bounds read. Attacking locally is a requirement. The exploit has been disclosed to the public and may be used. The project decided to collect all Fuzzer bugs in a main-issue to address them in the future. Affected versions
0.1
3.3
4.1.1
4.1.2
4.1.3
4.1.4
5.2.5
References Updated May 21, 2026 · Source: OSV.dev
CVE-2025-3549
PYSEC-2025-171
Apr 14, 2025
3.3
/ 10
Low
Local
Low
Low
None
Unchanged
None
None
Low
A vulnerability, which was classified as critical, was found in Open Asset Import Library Assimp 5.4.3. Affected is the function Assimp::MD3Importer::ValidateSurfaceHeaderOffsets of the file code/AssetLib/MD3/MD3Loader.cpp of the component File Handler. The manipulation leads to heap-based buffer overflow. The attack needs to be approached locally. The exploit has been disclosed to the public and may be used. Affected versions
0.1
3.3
4.1.1
4.1.2
4.1.3
4.1.4
5.2.5
References Updated May 21, 2026 · Source: OSV.dev
CVE-2025-3196
PYSEC-2025-170
Apr 04, 2025
5.5
/ 10
Medium
Local
Low
Low
None
Unchanged
None
None
High
A vulnerability, which was classified as critical, was found in Open Asset Import Library Assimp 5.4.3. Affected is the function Assimp::MD2Importer::InternReadFile in the library code/AssetLib/MD2/MD2Loader.cpp of the component Malformed File Handler. The manipulation of the argument Name leads to stack-based buffer overflow. The attack needs to be approached locally. The exploit has been disclosed to the public and may be used. It is recommended to upgrade the affected component. Affected versions
0.1
3.3
4.1.1
4.1.2
4.1.3
4.1.4
5.2.5
References Updated May 21, 2026 · Source: OSV.dev
CVE-2025-3160
PYSEC-2025-264
Apr 03, 2025
3.3
/ 10
Low
Local
Low
None
Required
Unchanged
Low
None
None
A vulnerability has been found in Open Asset Import Library Assimp 5.4.3 and classified as problematic. This vulnerability affects the function Assimp::SceneCombiner::AddNodeHashes of the file code/Common/SceneCombiner.cpp of the component File Handler. The manipulation leads to out-of-bounds read. An attack has to be approached locally. The exploit has been disclosed to the public and may be used. The patch is identified as a0993658f40d8e13ff5823990c30b43c82a5daf0. It is recommended to apply a patch to fix this issue. Affected versions
0.1
3.3
4.1.1
4.1.2
4.1.3
4.1.4
5.2.5
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-3159
PYSEC-2025-263
Apr 03, 2025
7.8
/ 10
High
Local
Low
None
Required
Unchanged
High
High
High
A vulnerability, which was classified as critical, was found in Open Asset Import Library Assimp 5.4.3. This affects the function Assimp::ASE::Parser::ParseLV4MeshBonesVertices of the file code/AssetLib/ASE/ASEParser.cpp of the component ASE File Handler. The manipulation leads to heap-based buffer overflow. The attack needs to be approached locally. The exploit has been disclosed to the public and may be used. The identifier of the patch is e8a6286542924e628e02749c4f5ac4f91fdae71b. It is recommended to apply a patch to fix this issue. Affected versions
0.1
3.3
4.1.1
4.1.2
4.1.3
4.1.4
5.2.5
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-3158
PYSEC-2025-169
Apr 03, 2025
7.8
/ 10
High
Local
Low
None
Required
Unchanged
High
High
High
A vulnerability, which was classified as critical, has been found in Open Asset Import Library Assimp 5.4.3. Affected by this issue is the function Assimp::LWO::AnimResolver::UpdateAnimRangeSetup of the file code/AssetLib/LWO/LWOAnimation.cpp of the component LWO File Handler. The manipulation leads to heap-based buffer overflow. It is possible to launch the attack on the local host. The exploit has been disclosed to the public and may be used. Affected versions
0.1
3.3
4.1.1
4.1.2
4.1.3
4.1.4
5.2.5
References Updated May 21, 2026 · Source: OSV.dev
CVE-2025-3016
PYSEC-2025-262
Mar 31, 2025
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
None
High
A vulnerability classified as problematic was found in Open Asset Import Library Assimp 5.4.3. This vulnerability affects the function Assimp::MDLImporter::ParseTextureColorData of the file code/AssetLib/MDL/MDLMaterialLoader.cpp of the component MDL File Handler. The manipulation of the argument mWidth/mHeight leads to resource consumption. The attack can be initiated remotely. Upgrading to version 6.0 is able to address this issue. The name of the patch is 5d2a7482312db2e866439a8c05a07ce1e718bed1. It is recommended to apply a patch to fix this issue. Affected versions
0.1
3.3
4.1.1
4.1.2
4.1.3
4.1.4
5.2.5
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-3015
PYSEC-2025-261
Mar 31, 2025
8.8
/ 10
High
Network
Low
None
Required
Unchanged
High
High
High
A vulnerability classified as critical has been found in Open Asset Import Library Assimp 5.4.3. This affects the function Assimp::ASEImporter::BuildUniqueRepresentation of the file code/AssetLib/ASE/ASELoader.cpp of the component ASE File Handler. The manipulation of the argument mIndices leads to out-of-bounds read. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 6.0 is able to address this issue. The patch is named 7c705fde418d68cca4e8eff56be01b2617b0d6fe. It is recommended to apply a patch to fix this issue. Affected versions
0.1
3.3
4.1.1
4.1.2
4.1.3
4.1.4
5.2.5
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-2757
PYSEC-2025-168
Mar 25, 2025
8.8
/ 10
High
Network
Low
None
Required
Unchanged
High
High
High
A vulnerability classified as critical was found in Open Asset Import Library Assimp 5.4.3. This vulnerability affects the function AI_MD5_PARSE_STRING_IN_QUOTATION of the file code/AssetLib/MD5/MD5Parser.cpp of the component MD5 File Handler. The manipulation of the argument data leads to heap-based buffer overflow. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. Affected versions
0.1
3.3
4.1.1
4.1.2
4.1.3
4.1.4
5.2.5
References Updated May 21, 2026 · Source: OSV.dev
CVE-2025-2756
PYSEC-2025-167
Mar 25, 2025
8.8
/ 10
High
Network
Low
None
Required
Unchanged
High
High
High
A vulnerability classified as critical has been found in Open Asset Import Library Assimp 5.4.3. This affects the function Assimp::AC3DImporter::ConvertObjectSection of the file code/AssetLib/AC/ACLoader.cpp of the component AC3D File Handler. The manipulation of the argument tmp leads to heap-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. Affected versions
0.1
3.3
4.1.1
4.1.2
4.1.3
4.1.4
5.2.5
References Updated May 21, 2026 · Source: OSV.dev
CVE-2025-2755
PYSEC-2025-166
Mar 25, 2025
8.8
/ 10
High
Network
Low
None
Required
Unchanged
High
High
High
A vulnerability was found in Open Asset Import Library Assimp 5.4.3. It has been rated as critical. Affected by this issue is the function Assimp::AC3DImporter::ConvertObjectSection of the file code/AssetLib/AC/ACLoader.cpp of the component AC3D File Handler. The manipulation of the argument src.entries leads to out-of-bounds read. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. Affected versions
0.1
3.3
4.1.1
4.1.2
4.1.3
4.1.4
5.2.5
References Updated May 21, 2026 · Source: OSV.dev
CVE-2025-2754
PYSEC-2025-165
Mar 25, 2025
8.8
/ 10
High
Network
Low
None
Required
Unchanged
High
High
High
A vulnerability was found in Open Asset Import Library Assimp 5.4.3. It has been declared as critical. Affected by this vulnerability is the function Assimp::AC3DImporter::ConvertObjectSection of the file code/AssetLib/AC/ACLoader.cpp of the component AC3D File Handler. The manipulation of the argument it leads to heap-based buffer overflow. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. Affected versions
0.1
3.3
4.1.1
4.1.2
4.1.3
4.1.4
5.2.5
References Updated May 21, 2026 · Source: OSV.dev
CVE-2025-2753
PYSEC-2025-164
Mar 25, 2025
8.8
/ 10
High
Network
Low
None
Required
Unchanged
High
High
High
A vulnerability was found in Open Asset Import Library Assimp 5.4.3. It has been classified as critical. Affected is the function SceneCombiner::MergeScenes of the file code/AssetLib/LWS/LWSLoader.cpp of the component LWS File Handler. The manipulation leads to out-of-bounds read. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. Affected versions
0.1
3.3
4.1.1
4.1.2
4.1.3
4.1.4
5.2.5
References Updated May 21, 2026 · Source: OSV.dev
CVE-2025-2752
PYSEC-2025-163
Mar 25, 2025
8.8
/ 10
High
Network
Low
None
Required
Unchanged
High
High
High
A vulnerability was found in Open Asset Import Library Assimp 5.4.3 and classified as problematic. This issue affects the function fast_atoreal_move in the library include/assimp/fast_atof.h of the component CSM File Handler. The manipulation leads to out-of-bounds read. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. Affected versions
0.1
3.3
4.1.1
4.1.2
4.1.3
4.1.4
5.2.5
References Updated May 21, 2026 · Source: OSV.dev
CVE-2025-2751
PYSEC-2025-162
Mar 25, 2025
8.8
/ 10
High
Network
Low
None
Required
Unchanged
High
High
High
A vulnerability has been found in Open Asset Import Library Assimp 5.4.3 and classified as problematic. This vulnerability affects the function Assimp::CSMImporter::InternReadFile of the file code/AssetLib/CSM/CSMLoader.cpp of the component CSM File Handler. The manipulation of the argument na leads to out-of-bounds read. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. Affected versions
0.1
3.3
4.1.1
4.1.2
4.1.3
4.1.4
5.2.5
References Updated May 21, 2026 · Source: OSV.dev
CVE-2025-2750
PYSEC-2025-161
Mar 25, 2025
8.8
/ 10
High
Network
Low
None
Required
Unchanged
High
High
High
A vulnerability, which was classified as critical, was found in Open Asset Import Library Assimp 5.4.3. This affects the function Assimp::CSMImporter::InternReadFile of the file code/AssetLib/CSM/CSMLoader.cpp of the component CSM File Handler. The manipulation leads to out-of-bounds write. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. Affected versions
0.1
3.3
4.1.1
4.1.2
4.1.3
4.1.4
5.2.5
References Updated May 21, 2026 · Source: OSV.dev
CVE-2025-2592
PYSEC-2025-260
Mar 21, 2025
8.8
/ 10
High
Network
Low
None
Required
Unchanged
High
High
High
A vulnerability, which was classified as critical, has been found in Open Asset Import Library Assimp 5.4.3. This issue affects the function CSMImporter::InternReadFile of the file code/AssetLib/CSM/CSMLoader.cpp. The manipulation leads to heap-based buffer overflow. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The patch is named 2690e354da0c681db000cfd892a55226788f2743. It is recommended to apply a patch to fix this issue. Affected versions
0.1
3.3
4.1.1
4.1.2
4.1.3
4.1.4
5.2.5
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-2591
PYSEC-2025-160
Mar 21, 2025
5.5
/ 10
Medium
Local
Low
None
Required
Unchanged
None
None
High
A vulnerability classified as problematic was found in Open Asset Import Library Assimp 5.4.3. This vulnerability affects the function MDLImporter::InternReadFile_Quake1 of the file code/AssetLib/MDL/MDLLoader.cpp. The manipulation of the argument skinwidth/skinheight leads to divide by zero. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The patch is identified as ab66a1674fcfac87aaba4c8b900b315ebc3e7dbd. It is recommended to apply a patch to fix this issue. Affected versions
0.1
3.3
4.1.1
4.1.2
4.1.3
4.1.4
5.2.5
References Updated May 21, 2026 · Source: OSV.dev
CVE-2025-2152
PYSEC-2025-159
Mar 10, 2025
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
A vulnerability, which was classified as critical, has been found in Open Asset Import Library Assimp 5.4.3. This issue affects the function Assimp::BaseImporter::ConvertToUTF8 of the file BaseImporter.cpp of the component File Handler. The manipulation leads to heap-based buffer overflow. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. Affected versions
0.1
3.3
4.1.1
4.1.2
4.1.3
4.1.4
5.2.5
References Updated May 21, 2026 · Source: OSV.dev
CVE-2025-2151
PYSEC-2025-158
Mar 10, 2025
8.8
/ 10
High
Network
Low
None
Required
Unchanged
High
High
High
A vulnerability classified as critical was found in Open Asset Import Library Assimp 5.4.3. This vulnerability affects the function Assimp::GetNextLine in the library ParsingUtils.h of the component File Handler. The manipulation leads to stack-based buffer overflow. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. Affected versions
0.1
3.3
4.1.1
4.1.2
4.1.3
4.1.4
5.2.5
References Updated May 21, 2026 · Source: OSV.dev
CVE-2024-53425
PYSEC-2024-295
Nov 21, 2024
6.2
/ 10
Medium
Local
Low
None
None
Unchanged
None
None
High
A heap-buffer-overflow vulnerability was discovered in the SkipSpacesAndLineEnd function in Assimp v5.4.3. This issue occurs when processing certain malformed MD5 model files, leading to an out-of-bounds read and potential application crash. Affected versions
0.1
3.3
4.1.1
4.1.2
4.1.3
4.1.4
5.2.5
References Updated May 21, 2026 · Source: OSV.dev
CVE-2024-48426
PYSEC-2024-294
Oct 24, 2024
6.2
/ 10
Medium
Local
Low
None
None
Unchanged
None
None
High
A segmentation fault (SEGV) was detected in the SortByPTypeProcess::Execute function in the Assimp library during fuzz testing with AddressSanitizer. The crash occurred due to a read access to an invalid memory address (0x1000c9714971). Affected versions
0.1
3.3
4.1.1
4.1.2
4.1.3
4.1.4
5.2.5
References Updated May 21, 2026 · Source: OSV.dev
CVE-2024-48425
PYSEC-2024-293
Oct 24, 2024
5.5
/ 10
Medium
Local
Low
Low
None
Unchanged
None
None
High
A segmentation fault (SEGV) was detected in the Assimp::SplitLargeMeshesProcess_Triangle::UpdateNode function within the Assimp library during fuzz testing using AddressSanitizer. The crash occurs due to a read access violation at address 0x000000000460, which points to the zero page, indicating a null or invalid pointer dereference. Affected versions
0.1
3.3
4.1.1
4.1.2
4.1.3
4.1.4
5.2.5
References Updated May 21, 2026 · Source: OSV.dev
CVE-2024-48424
PYSEC-2024-292
Oct 24, 2024
5.5
/ 10
Medium
Local
Low
Low
None
Unchanged
None
None
High
A heap-buffer-overflow vulnerability has been identified in the OpenDDLParser::parseStructure function within the Assimp library, specifically during the processing of OpenGEX files. Affected versions
0.1
3.3
4.1.1
4.1.2
4.1.3
4.1.4
5.2.5
References Updated May 21, 2026 · Source: OSV.dev
CVE-2024-48423
PYSEC-2024-120
Oct 24, 2024
7.8
/ 10
High
Local
Low
Low
None
Unchanged
High
High
High
An issue in assimp v.5.4.3 allows a local attacker to execute arbitrary code via the CallbackToLogRedirector function within the Assimp library. Affected versions
0.1
3.3
4.1.1
4.1.2
4.1.3
4.1.4
5.2.5
References Updated Nov 05, 2024 · Source: OSV.dev
CVE-2024-46632
PYSEC-2024-291
Sep 26, 2024
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
None
Low
Assimp v5.4.3 is vulnerable to Buffer Overflow via the MD5Importer::LoadMD5MeshFile function. Affected versions
0.1
3.3
4.1.1
4.1.2
4.1.3
4.1.4
5.2.5
References Updated May 21, 2026 · Source: OSV.dev | ||
4.1.4
patch
33 CVEs
CVE-2025-11277
PYSEC-2025-157
Oct 05, 2025
7.8
/ 10
High
Local
Low
Low
None
Unchanged
High
High
High
A weakness has been identified in Open Asset Import Library Assimp 6.0.2. This affects the function Q3DImporter::InternReadFile of the file assimp/code/AssetLib/Q3D/Q3DLoader.cpp. Executing a manipulation can lead to heap-based buffer overflow. The attack needs to be launched locally. The exploit has been made available to the public and could be used for attacks. Affected versions
0.1
3.3
4.1.1
4.1.2
4.1.3
4.1.4
5.2.5
References Updated May 21, 2026 · Source: OSV.dev
CVE-2025-11275
PYSEC-2025-156
Oct 05, 2025
7.8
/ 10
High
Local
Low
Low
None
Unchanged
High
High
High
A vulnerability was identified in Open Asset Import Library Assimp 6.0.2. Affected by this vulnerability is the function ODDLParser::getNextSeparator in the library assimp/contrib/openddlparser/include/openddlparser/OpenDDLParserUtils.h. Such manipulation leads to heap-based buffer overflow. The attack must be carried out locally. The exploit is publicly available and might be used. Affected versions
0.1
3.3
4.1.1
4.1.2
4.1.3
4.1.4
5.2.5
References Updated May 21, 2026 · Source: OSV.dev
CVE-2025-11274
PYSEC-2025-155
Oct 05, 2025
5.5
/ 10
Medium
Local
Low
Low
None
Unchanged
None
None
High
A vulnerability was determined in Open Asset Import Library Assimp 6.0.2. Affected is the function Q3DImporter::InternReadFile of the file assimp/code/AssetLib/Q3D/Q3DLoader.cpp. This manipulation causes allocation of resources. The attack is restricted to local execution. The exploit has been publicly disclosed and may be utilized. Affected versions
0.1
3.3
4.1.1
4.1.2
4.1.3
4.1.4
5.2.5
References Updated May 21, 2026 · Source: OSV.dev
CVE-2025-5169
PYSEC-2025-176
May 26, 2025
5.5
/ 10
Medium
Local
Low
Low
None
Unchanged
None
None
High
A vulnerability classified as problematic has been found in Open Asset Import Library Assimp 5.4.3. This affects the function MDLImporter::InternReadFile_3DGS_MDL345 of the file assimp/code/AssetLib/MDL/MDLLoader.cpp. The manipulation leads to out-of-bounds read. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used. The project decided to collect all Fuzzer bugs in a main-issue to address them in the future. Affected versions
0.1
3.3
4.1.1
4.1.2
4.1.3
4.1.4
5.2.5
References Updated May 21, 2026 · Source: OSV.dev
CVE-2025-5168
PYSEC-2025-175
May 26, 2025
5.5
/ 10
Medium
Local
Low
Low
None
Unchanged
None
None
High
A vulnerability was found in Open Asset Import Library Assimp 5.4.3. It has been rated as problematic. Affected by this issue is the function MDLImporter::ImportUVCoordinate_3DGS_MDL345 of the file assimp/code/AssetLib/MDL/MDLLoader.cpp. The manipulation of the argument iIndex leads to out-of-bounds read. An attack has to be approached locally. The exploit has been disclosed to the public and may be used. The project decided to collect all Fuzzer bugs in a main-issue to address them in the future. Affected versions
0.1
3.3
4.1.1
4.1.2
4.1.3
4.1.4
5.2.5
References Updated May 21, 2026 · Source: OSV.dev
CVE-2025-5167
PYSEC-2025-174
May 26, 2025
5.5
/ 10
Medium
Local
Low
Low
None
Unchanged
None
None
High
A vulnerability was found in Open Asset Import Library Assimp 5.4.3. It has been declared as problematic. Affected by this vulnerability is the function LWOImporter::GetS0 in the library assimp/code/AssetLib/LWO/LWOLoader.h. The manipulation of the argument out leads to out-of-bounds read. The attack needs to be approached locally. The exploit has been disclosed to the public and may be used. The project decided to collect all Fuzzer bugs in a main-issue to address them in the future. Affected versions
0.1
3.3
4.1.1
4.1.2
4.1.3
4.1.4
5.2.5
References Updated May 21, 2026 · Source: OSV.dev
CVE-2025-5166
PYSEC-2025-173
May 26, 2025
5.5
/ 10
Medium
Local
Low
Low
None
Unchanged
None
None
High
A vulnerability was found in Open Asset Import Library Assimp 5.4.3. It has been classified as problematic. Affected is the function MDCImporter::InternReadFile of the file assimp/code/AssetLib/MDC/MDCLoader.cpp of the component MDC File Parser. The manipulation of the argument pcVerts leads to out-of-bounds read. It is possible to launch the attack on the local host. The exploit has been disclosed to the public and may be used. The project decided to collect all Fuzzer bugs in a main-issue to address them in the future. Affected versions
0.1
3.3
4.1.1
4.1.2
4.1.3
4.1.4
5.2.5
References Updated May 21, 2026 · Source: OSV.dev
CVE-2025-5165
PYSEC-2025-172
May 26, 2025
5.5
/ 10
Medium
Local
Low
Low
None
Unchanged
None
None
High
A vulnerability was found in Open Asset Import Library Assimp 5.4.3 and classified as problematic. This issue affects the function MDCImporter::ValidateSurfaceHeader of the file assimp/code/AssetLib/MDC/MDCLoader.cpp. The manipulation of the argument pcSurface2 leads to out-of-bounds read. Attacking locally is a requirement. The exploit has been disclosed to the public and may be used. The project decided to collect all Fuzzer bugs in a main-issue to address them in the future. Affected versions
0.1
3.3
4.1.1
4.1.2
4.1.3
4.1.4
5.2.5
References Updated May 21, 2026 · Source: OSV.dev
CVE-2025-3549
PYSEC-2025-171
Apr 14, 2025
3.3
/ 10
Low
Local
Low
Low
None
Unchanged
None
None
Low
A vulnerability, which was classified as critical, was found in Open Asset Import Library Assimp 5.4.3. Affected is the function Assimp::MD3Importer::ValidateSurfaceHeaderOffsets of the file code/AssetLib/MD3/MD3Loader.cpp of the component File Handler. The manipulation leads to heap-based buffer overflow. The attack needs to be approached locally. The exploit has been disclosed to the public and may be used. Affected versions
0.1
3.3
4.1.1
4.1.2
4.1.3
4.1.4
5.2.5
References Updated May 21, 2026 · Source: OSV.dev
CVE-2025-3196
PYSEC-2025-170
Apr 04, 2025
5.5
/ 10
Medium
Local
Low
Low
None
Unchanged
None
None
High
A vulnerability, which was classified as critical, was found in Open Asset Import Library Assimp 5.4.3. Affected is the function Assimp::MD2Importer::InternReadFile in the library code/AssetLib/MD2/MD2Loader.cpp of the component Malformed File Handler. The manipulation of the argument Name leads to stack-based buffer overflow. The attack needs to be approached locally. The exploit has been disclosed to the public and may be used. It is recommended to upgrade the affected component. Affected versions
0.1
3.3
4.1.1
4.1.2
4.1.3
4.1.4
5.2.5
References Updated May 21, 2026 · Source: OSV.dev
CVE-2025-3160
PYSEC-2025-264
Apr 03, 2025
3.3
/ 10
Low
Local
Low
None
Required
Unchanged
Low
None
None
A vulnerability has been found in Open Asset Import Library Assimp 5.4.3 and classified as problematic. This vulnerability affects the function Assimp::SceneCombiner::AddNodeHashes of the file code/Common/SceneCombiner.cpp of the component File Handler. The manipulation leads to out-of-bounds read. An attack has to be approached locally. The exploit has been disclosed to the public and may be used. The patch is identified as a0993658f40d8e13ff5823990c30b43c82a5daf0. It is recommended to apply a patch to fix this issue. Affected versions
0.1
3.3
4.1.1
4.1.2
4.1.3
4.1.4
5.2.5
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-3159
PYSEC-2025-263
Apr 03, 2025
7.8
/ 10
High
Local
Low
None
Required
Unchanged
High
High
High
A vulnerability, which was classified as critical, was found in Open Asset Import Library Assimp 5.4.3. This affects the function Assimp::ASE::Parser::ParseLV4MeshBonesVertices of the file code/AssetLib/ASE/ASEParser.cpp of the component ASE File Handler. The manipulation leads to heap-based buffer overflow. The attack needs to be approached locally. The exploit has been disclosed to the public and may be used. The identifier of the patch is e8a6286542924e628e02749c4f5ac4f91fdae71b. It is recommended to apply a patch to fix this issue. Affected versions
0.1
3.3
4.1.1
4.1.2
4.1.3
4.1.4
5.2.5
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-3158
PYSEC-2025-169
Apr 03, 2025
7.8
/ 10
High
Local
Low
None
Required
Unchanged
High
High
High
A vulnerability, which was classified as critical, has been found in Open Asset Import Library Assimp 5.4.3. Affected by this issue is the function Assimp::LWO::AnimResolver::UpdateAnimRangeSetup of the file code/AssetLib/LWO/LWOAnimation.cpp of the component LWO File Handler. The manipulation leads to heap-based buffer overflow. It is possible to launch the attack on the local host. The exploit has been disclosed to the public and may be used. Affected versions
0.1
3.3
4.1.1
4.1.2
4.1.3
4.1.4
5.2.5
References Updated May 21, 2026 · Source: OSV.dev
CVE-2025-3016
PYSEC-2025-262
Mar 31, 2025
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
None
High
A vulnerability classified as problematic was found in Open Asset Import Library Assimp 5.4.3. This vulnerability affects the function Assimp::MDLImporter::ParseTextureColorData of the file code/AssetLib/MDL/MDLMaterialLoader.cpp of the component MDL File Handler. The manipulation of the argument mWidth/mHeight leads to resource consumption. The attack can be initiated remotely. Upgrading to version 6.0 is able to address this issue. The name of the patch is 5d2a7482312db2e866439a8c05a07ce1e718bed1. It is recommended to apply a patch to fix this issue. Affected versions
0.1
3.3
4.1.1
4.1.2
4.1.3
4.1.4
5.2.5
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-3015
PYSEC-2025-261
Mar 31, 2025
8.8
/ 10
High
Network
Low
None
Required
Unchanged
High
High
High
A vulnerability classified as critical has been found in Open Asset Import Library Assimp 5.4.3. This affects the function Assimp::ASEImporter::BuildUniqueRepresentation of the file code/AssetLib/ASE/ASELoader.cpp of the component ASE File Handler. The manipulation of the argument mIndices leads to out-of-bounds read. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 6.0 is able to address this issue. The patch is named 7c705fde418d68cca4e8eff56be01b2617b0d6fe. It is recommended to apply a patch to fix this issue. Affected versions
0.1
3.3
4.1.1
4.1.2
4.1.3
4.1.4
5.2.5
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-2757
PYSEC-2025-168
Mar 25, 2025
8.8
/ 10
High
Network
Low
None
Required
Unchanged
High
High
High
A vulnerability classified as critical was found in Open Asset Import Library Assimp 5.4.3. This vulnerability affects the function AI_MD5_PARSE_STRING_IN_QUOTATION of the file code/AssetLib/MD5/MD5Parser.cpp of the component MD5 File Handler. The manipulation of the argument data leads to heap-based buffer overflow. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. Affected versions
0.1
3.3
4.1.1
4.1.2
4.1.3
4.1.4
5.2.5
References Updated May 21, 2026 · Source: OSV.dev
CVE-2025-2756
PYSEC-2025-167
Mar 25, 2025
8.8
/ 10
High
Network
Low
None
Required
Unchanged
High
High
High
A vulnerability classified as critical has been found in Open Asset Import Library Assimp 5.4.3. This affects the function Assimp::AC3DImporter::ConvertObjectSection of the file code/AssetLib/AC/ACLoader.cpp of the component AC3D File Handler. The manipulation of the argument tmp leads to heap-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. Affected versions
0.1
3.3
4.1.1
4.1.2
4.1.3
4.1.4
5.2.5
References Updated May 21, 2026 · Source: OSV.dev
CVE-2025-2755
PYSEC-2025-166
Mar 25, 2025
8.8
/ 10
High
Network
Low
None
Required
Unchanged
High
High
High
A vulnerability was found in Open Asset Import Library Assimp 5.4.3. It has been rated as critical. Affected by this issue is the function Assimp::AC3DImporter::ConvertObjectSection of the file code/AssetLib/AC/ACLoader.cpp of the component AC3D File Handler. The manipulation of the argument src.entries leads to out-of-bounds read. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. Affected versions
0.1
3.3
4.1.1
4.1.2
4.1.3
4.1.4
5.2.5
References Updated May 21, 2026 · Source: OSV.dev
CVE-2025-2754
PYSEC-2025-165
Mar 25, 2025
8.8
/ 10
High
Network
Low
None
Required
Unchanged
High
High
High
A vulnerability was found in Open Asset Import Library Assimp 5.4.3. It has been declared as critical. Affected by this vulnerability is the function Assimp::AC3DImporter::ConvertObjectSection of the file code/AssetLib/AC/ACLoader.cpp of the component AC3D File Handler. The manipulation of the argument it leads to heap-based buffer overflow. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. Affected versions
0.1
3.3
4.1.1
4.1.2
4.1.3
4.1.4
5.2.5
References Updated May 21, 2026 · Source: OSV.dev
CVE-2025-2753
PYSEC-2025-164
Mar 25, 2025
8.8
/ 10
High
Network
Low
None
Required
Unchanged
High
High
High
A vulnerability was found in Open Asset Import Library Assimp 5.4.3. It has been classified as critical. Affected is the function SceneCombiner::MergeScenes of the file code/AssetLib/LWS/LWSLoader.cpp of the component LWS File Handler. The manipulation leads to out-of-bounds read. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. Affected versions
0.1
3.3
4.1.1
4.1.2
4.1.3
4.1.4
5.2.5
References Updated May 21, 2026 · Source: OSV.dev
CVE-2025-2752
PYSEC-2025-163
Mar 25, 2025
8.8
/ 10
High
Network
Low
None
Required
Unchanged
High
High
High
A vulnerability was found in Open Asset Import Library Assimp 5.4.3 and classified as problematic. This issue affects the function fast_atoreal_move in the library include/assimp/fast_atof.h of the component CSM File Handler. The manipulation leads to out-of-bounds read. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. Affected versions
0.1
3.3
4.1.1
4.1.2
4.1.3
4.1.4
5.2.5
References Updated May 21, 2026 · Source: OSV.dev
CVE-2025-2751
PYSEC-2025-162
Mar 25, 2025
8.8
/ 10
High
Network
Low
None
Required
Unchanged
High
High
High
A vulnerability has been found in Open Asset Import Library Assimp 5.4.3 and classified as problematic. This vulnerability affects the function Assimp::CSMImporter::InternReadFile of the file code/AssetLib/CSM/CSMLoader.cpp of the component CSM File Handler. The manipulation of the argument na leads to out-of-bounds read. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. Affected versions
0.1
3.3
4.1.1
4.1.2
4.1.3
4.1.4
5.2.5
References Updated May 21, 2026 · Source: OSV.dev
CVE-2025-2750
PYSEC-2025-161
Mar 25, 2025
8.8
/ 10
High
Network
Low
None
Required
Unchanged
High
High
High
A vulnerability, which was classified as critical, was found in Open Asset Import Library Assimp 5.4.3. This affects the function Assimp::CSMImporter::InternReadFile of the file code/AssetLib/CSM/CSMLoader.cpp of the component CSM File Handler. The manipulation leads to out-of-bounds write. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. Affected versions
0.1
3.3
4.1.1
4.1.2
4.1.3
4.1.4
5.2.5
References Updated May 21, 2026 · Source: OSV.dev
CVE-2025-2592
PYSEC-2025-260
Mar 21, 2025
8.8
/ 10
High
Network
Low
None
Required
Unchanged
High
High
High
A vulnerability, which was classified as critical, has been found in Open Asset Import Library Assimp 5.4.3. This issue affects the function CSMImporter::InternReadFile of the file code/AssetLib/CSM/CSMLoader.cpp. The manipulation leads to heap-based buffer overflow. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The patch is named 2690e354da0c681db000cfd892a55226788f2743. It is recommended to apply a patch to fix this issue. Affected versions
0.1
3.3
4.1.1
4.1.2
4.1.3
4.1.4
5.2.5
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-2591
PYSEC-2025-160
Mar 21, 2025
5.5
/ 10
Medium
Local
Low
None
Required
Unchanged
None
None
High
A vulnerability classified as problematic was found in Open Asset Import Library Assimp 5.4.3. This vulnerability affects the function MDLImporter::InternReadFile_Quake1 of the file code/AssetLib/MDL/MDLLoader.cpp. The manipulation of the argument skinwidth/skinheight leads to divide by zero. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The patch is identified as ab66a1674fcfac87aaba4c8b900b315ebc3e7dbd. It is recommended to apply a patch to fix this issue. Affected versions
0.1
3.3
4.1.1
4.1.2
4.1.3
4.1.4
5.2.5
References Updated May 21, 2026 · Source: OSV.dev
CVE-2025-2152
PYSEC-2025-159
Mar 10, 2025
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
A vulnerability, which was classified as critical, has been found in Open Asset Import Library Assimp 5.4.3. This issue affects the function Assimp::BaseImporter::ConvertToUTF8 of the file BaseImporter.cpp of the component File Handler. The manipulation leads to heap-based buffer overflow. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. Affected versions
0.1
3.3
4.1.1
4.1.2
4.1.3
4.1.4
5.2.5
References Updated May 21, 2026 · Source: OSV.dev
CVE-2025-2151
PYSEC-2025-158
Mar 10, 2025
8.8
/ 10
High
Network
Low
None
Required
Unchanged
High
High
High
A vulnerability classified as critical was found in Open Asset Import Library Assimp 5.4.3. This vulnerability affects the function Assimp::GetNextLine in the library ParsingUtils.h of the component File Handler. The manipulation leads to stack-based buffer overflow. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. Affected versions
0.1
3.3
4.1.1
4.1.2
4.1.3
4.1.4
5.2.5
References Updated May 21, 2026 · Source: OSV.dev
CVE-2024-53425
PYSEC-2024-295
Nov 21, 2024
6.2
/ 10
Medium
Local
Low
None
None
Unchanged
None
None
High
A heap-buffer-overflow vulnerability was discovered in the SkipSpacesAndLineEnd function in Assimp v5.4.3. This issue occurs when processing certain malformed MD5 model files, leading to an out-of-bounds read and potential application crash. Affected versions
0.1
3.3
4.1.1
4.1.2
4.1.3
4.1.4
5.2.5
References Updated May 21, 2026 · Source: OSV.dev
CVE-2024-48426
PYSEC-2024-294
Oct 24, 2024
6.2
/ 10
Medium
Local
Low
None
None
Unchanged
None
None
High
A segmentation fault (SEGV) was detected in the SortByPTypeProcess::Execute function in the Assimp library during fuzz testing with AddressSanitizer. The crash occurred due to a read access to an invalid memory address (0x1000c9714971). Affected versions
0.1
3.3
4.1.1
4.1.2
4.1.3
4.1.4
5.2.5
References Updated May 21, 2026 · Source: OSV.dev
CVE-2024-48425
PYSEC-2024-293
Oct 24, 2024
5.5
/ 10
Medium
Local
Low
Low
None
Unchanged
None
None
High
A segmentation fault (SEGV) was detected in the Assimp::SplitLargeMeshesProcess_Triangle::UpdateNode function within the Assimp library during fuzz testing using AddressSanitizer. The crash occurs due to a read access violation at address 0x000000000460, which points to the zero page, indicating a null or invalid pointer dereference. Affected versions
0.1
3.3
4.1.1
4.1.2
4.1.3
4.1.4
5.2.5
References Updated May 21, 2026 · Source: OSV.dev
CVE-2024-48424
PYSEC-2024-292
Oct 24, 2024
5.5
/ 10
Medium
Local
Low
Low
None
Unchanged
None
None
High
A heap-buffer-overflow vulnerability has been identified in the OpenDDLParser::parseStructure function within the Assimp library, specifically during the processing of OpenGEX files. Affected versions
0.1
3.3
4.1.1
4.1.2
4.1.3
4.1.4
5.2.5
References Updated May 21, 2026 · Source: OSV.dev
CVE-2024-48423
PYSEC-2024-120
Oct 24, 2024
7.8
/ 10
High
Local
Low
Low
None
Unchanged
High
High
High
An issue in assimp v.5.4.3 allows a local attacker to execute arbitrary code via the CallbackToLogRedirector function within the Assimp library. Affected versions
0.1
3.3
4.1.1
4.1.2
4.1.3
4.1.4
5.2.5
References Updated Nov 05, 2024 · Source: OSV.dev
CVE-2024-46632
PYSEC-2024-291
Sep 26, 2024
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
None
Low
Assimp v5.4.3 is vulnerable to Buffer Overflow via the MD5Importer::LoadMD5MeshFile function. Affected versions
0.1
3.3
4.1.1
4.1.2
4.1.3
4.1.4
5.2.5
References Updated May 21, 2026 · Source: OSV.dev | ||
4.1.3
patch
33 CVEs
CVE-2025-11277
PYSEC-2025-157
Oct 05, 2025
7.8
/ 10
High
Local
Low
Low
None
Unchanged
High
High
High
A weakness has been identified in Open Asset Import Library Assimp 6.0.2. This affects the function Q3DImporter::InternReadFile of the file assimp/code/AssetLib/Q3D/Q3DLoader.cpp. Executing a manipulation can lead to heap-based buffer overflow. The attack needs to be launched locally. The exploit has been made available to the public and could be used for attacks. Affected versions
0.1
3.3
4.1.1
4.1.2
4.1.3
4.1.4
5.2.5
References Updated May 21, 2026 · Source: OSV.dev
CVE-2025-11275
PYSEC-2025-156
Oct 05, 2025
7.8
/ 10
High
Local
Low
Low
None
Unchanged
High
High
High
A vulnerability was identified in Open Asset Import Library Assimp 6.0.2. Affected by this vulnerability is the function ODDLParser::getNextSeparator in the library assimp/contrib/openddlparser/include/openddlparser/OpenDDLParserUtils.h. Such manipulation leads to heap-based buffer overflow. The attack must be carried out locally. The exploit is publicly available and might be used. Affected versions
0.1
3.3
4.1.1
4.1.2
4.1.3
4.1.4
5.2.5
References Updated May 21, 2026 · Source: OSV.dev
CVE-2025-11274
PYSEC-2025-155
Oct 05, 2025
5.5
/ 10
Medium
Local
Low
Low
None
Unchanged
None
None
High
A vulnerability was determined in Open Asset Import Library Assimp 6.0.2. Affected is the function Q3DImporter::InternReadFile of the file assimp/code/AssetLib/Q3D/Q3DLoader.cpp. This manipulation causes allocation of resources. The attack is restricted to local execution. The exploit has been publicly disclosed and may be utilized. Affected versions
0.1
3.3
4.1.1
4.1.2
4.1.3
4.1.4
5.2.5
References Updated May 21, 2026 · Source: OSV.dev
CVE-2025-5169
PYSEC-2025-176
May 26, 2025
5.5
/ 10
Medium
Local
Low
Low
None
Unchanged
None
None
High
A vulnerability classified as problematic has been found in Open Asset Import Library Assimp 5.4.3. This affects the function MDLImporter::InternReadFile_3DGS_MDL345 of the file assimp/code/AssetLib/MDL/MDLLoader.cpp. The manipulation leads to out-of-bounds read. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used. The project decided to collect all Fuzzer bugs in a main-issue to address them in the future. Affected versions
0.1
3.3
4.1.1
4.1.2
4.1.3
4.1.4
5.2.5
References Updated May 21, 2026 · Source: OSV.dev
CVE-2025-5168
PYSEC-2025-175
May 26, 2025
5.5
/ 10
Medium
Local
Low
Low
None
Unchanged
None
None
High
A vulnerability was found in Open Asset Import Library Assimp 5.4.3. It has been rated as problematic. Affected by this issue is the function MDLImporter::ImportUVCoordinate_3DGS_MDL345 of the file assimp/code/AssetLib/MDL/MDLLoader.cpp. The manipulation of the argument iIndex leads to out-of-bounds read. An attack has to be approached locally. The exploit has been disclosed to the public and may be used. The project decided to collect all Fuzzer bugs in a main-issue to address them in the future. Affected versions
0.1
3.3
4.1.1
4.1.2
4.1.3
4.1.4
5.2.5
References Updated May 21, 2026 · Source: OSV.dev
CVE-2025-5167
PYSEC-2025-174
May 26, 2025
5.5
/ 10
Medium
Local
Low
Low
None
Unchanged
None
None
High
A vulnerability was found in Open Asset Import Library Assimp 5.4.3. It has been declared as problematic. Affected by this vulnerability is the function LWOImporter::GetS0 in the library assimp/code/AssetLib/LWO/LWOLoader.h. The manipulation of the argument out leads to out-of-bounds read. The attack needs to be approached locally. The exploit has been disclosed to the public and may be used. The project decided to collect all Fuzzer bugs in a main-issue to address them in the future. Affected versions
0.1
3.3
4.1.1
4.1.2
4.1.3
4.1.4
5.2.5
References Updated May 21, 2026 · Source: OSV.dev
CVE-2025-5166
PYSEC-2025-173
May 26, 2025
5.5
/ 10
Medium
Local
Low
Low
None
Unchanged
None
None
High
A vulnerability was found in Open Asset Import Library Assimp 5.4.3. It has been classified as problematic. Affected is the function MDCImporter::InternReadFile of the file assimp/code/AssetLib/MDC/MDCLoader.cpp of the component MDC File Parser. The manipulation of the argument pcVerts leads to out-of-bounds read. It is possible to launch the attack on the local host. The exploit has been disclosed to the public and may be used. The project decided to collect all Fuzzer bugs in a main-issue to address them in the future. Affected versions
0.1
3.3
4.1.1
4.1.2
4.1.3
4.1.4
5.2.5
References Updated May 21, 2026 · Source: OSV.dev
CVE-2025-5165
PYSEC-2025-172
May 26, 2025
5.5
/ 10
Medium
Local
Low
Low
None
Unchanged
None
None
High
A vulnerability was found in Open Asset Import Library Assimp 5.4.3 and classified as problematic. This issue affects the function MDCImporter::ValidateSurfaceHeader of the file assimp/code/AssetLib/MDC/MDCLoader.cpp. The manipulation of the argument pcSurface2 leads to out-of-bounds read. Attacking locally is a requirement. The exploit has been disclosed to the public and may be used. The project decided to collect all Fuzzer bugs in a main-issue to address them in the future. Affected versions
0.1
3.3
4.1.1
4.1.2
4.1.3
4.1.4
5.2.5
References Updated May 21, 2026 · Source: OSV.dev
CVE-2025-3549
PYSEC-2025-171
Apr 14, 2025
3.3
/ 10
Low
Local
Low
Low
None
Unchanged
None
None
Low
A vulnerability, which was classified as critical, was found in Open Asset Import Library Assimp 5.4.3. Affected is the function Assimp::MD3Importer::ValidateSurfaceHeaderOffsets of the file code/AssetLib/MD3/MD3Loader.cpp of the component File Handler. The manipulation leads to heap-based buffer overflow. The attack needs to be approached locally. The exploit has been disclosed to the public and may be used. Affected versions
0.1
3.3
4.1.1
4.1.2
4.1.3
4.1.4
5.2.5
References Updated May 21, 2026 · Source: OSV.dev
CVE-2025-3196
PYSEC-2025-170
Apr 04, 2025
5.5
/ 10
Medium
Local
Low
Low
None
Unchanged
None
None
High
A vulnerability, which was classified as critical, was found in Open Asset Import Library Assimp 5.4.3. Affected is the function Assimp::MD2Importer::InternReadFile in the library code/AssetLib/MD2/MD2Loader.cpp of the component Malformed File Handler. The manipulation of the argument Name leads to stack-based buffer overflow. The attack needs to be approached locally. The exploit has been disclosed to the public and may be used. It is recommended to upgrade the affected component. Affected versions
0.1
3.3
4.1.1
4.1.2
4.1.3
4.1.4
5.2.5
References Updated May 21, 2026 · Source: OSV.dev
CVE-2025-3160
PYSEC-2025-264
Apr 03, 2025
3.3
/ 10
Low
Local
Low
None
Required
Unchanged
Low
None
None
A vulnerability has been found in Open Asset Import Library Assimp 5.4.3 and classified as problematic. This vulnerability affects the function Assimp::SceneCombiner::AddNodeHashes of the file code/Common/SceneCombiner.cpp of the component File Handler. The manipulation leads to out-of-bounds read. An attack has to be approached locally. The exploit has been disclosed to the public and may be used. The patch is identified as a0993658f40d8e13ff5823990c30b43c82a5daf0. It is recommended to apply a patch to fix this issue. Affected versions
0.1
3.3
4.1.1
4.1.2
4.1.3
4.1.4
5.2.5
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-3159
PYSEC-2025-263
Apr 03, 2025
7.8
/ 10
High
Local
Low
None
Required
Unchanged
High
High
High
A vulnerability, which was classified as critical, was found in Open Asset Import Library Assimp 5.4.3. This affects the function Assimp::ASE::Parser::ParseLV4MeshBonesVertices of the file code/AssetLib/ASE/ASEParser.cpp of the component ASE File Handler. The manipulation leads to heap-based buffer overflow. The attack needs to be approached locally. The exploit has been disclosed to the public and may be used. The identifier of the patch is e8a6286542924e628e02749c4f5ac4f91fdae71b. It is recommended to apply a patch to fix this issue. Affected versions
0.1
3.3
4.1.1
4.1.2
4.1.3
4.1.4
5.2.5
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-3158
PYSEC-2025-169
Apr 03, 2025
7.8
/ 10
High
Local
Low
None
Required
Unchanged
High
High
High
A vulnerability, which was classified as critical, has been found in Open Asset Import Library Assimp 5.4.3. Affected by this issue is the function Assimp::LWO::AnimResolver::UpdateAnimRangeSetup of the file code/AssetLib/LWO/LWOAnimation.cpp of the component LWO File Handler. The manipulation leads to heap-based buffer overflow. It is possible to launch the attack on the local host. The exploit has been disclosed to the public and may be used. Affected versions
0.1
3.3
4.1.1
4.1.2
4.1.3
4.1.4
5.2.5
References Updated May 21, 2026 · Source: OSV.dev
CVE-2025-3016
PYSEC-2025-262
Mar 31, 2025
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
None
High
A vulnerability classified as problematic was found in Open Asset Import Library Assimp 5.4.3. This vulnerability affects the function Assimp::MDLImporter::ParseTextureColorData of the file code/AssetLib/MDL/MDLMaterialLoader.cpp of the component MDL File Handler. The manipulation of the argument mWidth/mHeight leads to resource consumption. The attack can be initiated remotely. Upgrading to version 6.0 is able to address this issue. The name of the patch is 5d2a7482312db2e866439a8c05a07ce1e718bed1. It is recommended to apply a patch to fix this issue. Affected versions
0.1
3.3
4.1.1
4.1.2
4.1.3
4.1.4
5.2.5
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-3015
PYSEC-2025-261
Mar 31, 2025
8.8
/ 10
High
Network
Low
None
Required
Unchanged
High
High
High
A vulnerability classified as critical has been found in Open Asset Import Library Assimp 5.4.3. This affects the function Assimp::ASEImporter::BuildUniqueRepresentation of the file code/AssetLib/ASE/ASELoader.cpp of the component ASE File Handler. The manipulation of the argument mIndices leads to out-of-bounds read. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 6.0 is able to address this issue. The patch is named 7c705fde418d68cca4e8eff56be01b2617b0d6fe. It is recommended to apply a patch to fix this issue. Affected versions
0.1
3.3
4.1.1
4.1.2
4.1.3
4.1.4
5.2.5
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-2757
PYSEC-2025-168
Mar 25, 2025
8.8
/ 10
High
Network
Low
None
Required
Unchanged
High
High
High
A vulnerability classified as critical was found in Open Asset Import Library Assimp 5.4.3. This vulnerability affects the function AI_MD5_PARSE_STRING_IN_QUOTATION of the file code/AssetLib/MD5/MD5Parser.cpp of the component MD5 File Handler. The manipulation of the argument data leads to heap-based buffer overflow. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. Affected versions
0.1
3.3
4.1.1
4.1.2
4.1.3
4.1.4
5.2.5
References Updated May 21, 2026 · Source: OSV.dev
CVE-2025-2756
PYSEC-2025-167
Mar 25, 2025
8.8
/ 10
High
Network
Low
None
Required
Unchanged
High
High
High
A vulnerability classified as critical has been found in Open Asset Import Library Assimp 5.4.3. This affects the function Assimp::AC3DImporter::ConvertObjectSection of the file code/AssetLib/AC/ACLoader.cpp of the component AC3D File Handler. The manipulation of the argument tmp leads to heap-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. Affected versions
0.1
3.3
4.1.1
4.1.2
4.1.3
4.1.4
5.2.5
References Updated May 21, 2026 · Source: OSV.dev
CVE-2025-2755
PYSEC-2025-166
Mar 25, 2025
8.8
/ 10
High
Network
Low
None
Required
Unchanged
High
High
High
A vulnerability was found in Open Asset Import Library Assimp 5.4.3. It has been rated as critical. Affected by this issue is the function Assimp::AC3DImporter::ConvertObjectSection of the file code/AssetLib/AC/ACLoader.cpp of the component AC3D File Handler. The manipulation of the argument src.entries leads to out-of-bounds read. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. Affected versions
0.1
3.3
4.1.1
4.1.2
4.1.3
4.1.4
5.2.5
References Updated May 21, 2026 · Source: OSV.dev
CVE-2025-2754
PYSEC-2025-165
Mar 25, 2025
8.8
/ 10
High
Network
Low
None
Required
Unchanged
High
High
High
A vulnerability was found in Open Asset Import Library Assimp 5.4.3. It has been declared as critical. Affected by this vulnerability is the function Assimp::AC3DImporter::ConvertObjectSection of the file code/AssetLib/AC/ACLoader.cpp of the component AC3D File Handler. The manipulation of the argument it leads to heap-based buffer overflow. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. Affected versions
0.1
3.3
4.1.1
4.1.2
4.1.3
4.1.4
5.2.5
References Updated May 21, 2026 · Source: OSV.dev
CVE-2025-2753
PYSEC-2025-164
Mar 25, 2025
8.8
/ 10
High
Network
Low
None
Required
Unchanged
High
High
High
A vulnerability was found in Open Asset Import Library Assimp 5.4.3. It has been classified as critical. Affected is the function SceneCombiner::MergeScenes of the file code/AssetLib/LWS/LWSLoader.cpp of the component LWS File Handler. The manipulation leads to out-of-bounds read. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. Affected versions
0.1
3.3
4.1.1
4.1.2
4.1.3
4.1.4
5.2.5
References Updated May 21, 2026 · Source: OSV.dev
CVE-2025-2752
PYSEC-2025-163
Mar 25, 2025
8.8
/ 10
High
Network
Low
None
Required
Unchanged
High
High
High
A vulnerability was found in Open Asset Import Library Assimp 5.4.3 and classified as problematic. This issue affects the function fast_atoreal_move in the library include/assimp/fast_atof.h of the component CSM File Handler. The manipulation leads to out-of-bounds read. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. Affected versions
0.1
3.3
4.1.1
4.1.2
4.1.3
4.1.4
5.2.5
References Updated May 21, 2026 · Source: OSV.dev
CVE-2025-2751
PYSEC-2025-162
Mar 25, 2025
8.8
/ 10
High
Network
Low
None
Required
Unchanged
High
High
High
A vulnerability has been found in Open Asset Import Library Assimp 5.4.3 and classified as problematic. This vulnerability affects the function Assimp::CSMImporter::InternReadFile of the file code/AssetLib/CSM/CSMLoader.cpp of the component CSM File Handler. The manipulation of the argument na leads to out-of-bounds read. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. Affected versions
0.1
3.3
4.1.1
4.1.2
4.1.3
4.1.4
5.2.5
References Updated May 21, 2026 · Source: OSV.dev
CVE-2025-2750
PYSEC-2025-161
Mar 25, 2025
8.8
/ 10
High
Network
Low
None
Required
Unchanged
High
High
High
A vulnerability, which was classified as critical, was found in Open Asset Import Library Assimp 5.4.3. This affects the function Assimp::CSMImporter::InternReadFile of the file code/AssetLib/CSM/CSMLoader.cpp of the component CSM File Handler. The manipulation leads to out-of-bounds write. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. Affected versions
0.1
3.3
4.1.1
4.1.2
4.1.3
4.1.4
5.2.5
References Updated May 21, 2026 · Source: OSV.dev
CVE-2025-2592
PYSEC-2025-260
Mar 21, 2025
8.8
/ 10
High
Network
Low
None
Required
Unchanged
High
High
High
A vulnerability, which was classified as critical, has been found in Open Asset Import Library Assimp 5.4.3. This issue affects the function CSMImporter::InternReadFile of the file code/AssetLib/CSM/CSMLoader.cpp. The manipulation leads to heap-based buffer overflow. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The patch is named 2690e354da0c681db000cfd892a55226788f2743. It is recommended to apply a patch to fix this issue. Affected versions
0.1
3.3
4.1.1
4.1.2
4.1.3
4.1.4
5.2.5
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-2591
PYSEC-2025-160
Mar 21, 2025
5.5
/ 10
Medium
Local
Low
None
Required
Unchanged
None
None
High
A vulnerability classified as problematic was found in Open Asset Import Library Assimp 5.4.3. This vulnerability affects the function MDLImporter::InternReadFile_Quake1 of the file code/AssetLib/MDL/MDLLoader.cpp. The manipulation of the argument skinwidth/skinheight leads to divide by zero. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The patch is identified as ab66a1674fcfac87aaba4c8b900b315ebc3e7dbd. It is recommended to apply a patch to fix this issue. Affected versions
0.1
3.3
4.1.1
4.1.2
4.1.3
4.1.4
5.2.5
References Updated May 21, 2026 · Source: OSV.dev
CVE-2025-2152
PYSEC-2025-159
Mar 10, 2025
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
A vulnerability, which was classified as critical, has been found in Open Asset Import Library Assimp 5.4.3. This issue affects the function Assimp::BaseImporter::ConvertToUTF8 of the file BaseImporter.cpp of the component File Handler. The manipulation leads to heap-based buffer overflow. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. Affected versions
0.1
3.3
4.1.1
4.1.2
4.1.3
4.1.4
5.2.5
References Updated May 21, 2026 · Source: OSV.dev
CVE-2025-2151
PYSEC-2025-158
Mar 10, 2025
8.8
/ 10
High
Network
Low
None
Required
Unchanged
High
High
High
A vulnerability classified as critical was found in Open Asset Import Library Assimp 5.4.3. This vulnerability affects the function Assimp::GetNextLine in the library ParsingUtils.h of the component File Handler. The manipulation leads to stack-based buffer overflow. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. Affected versions
0.1
3.3
4.1.1
4.1.2
4.1.3
4.1.4
5.2.5
References Updated May 21, 2026 · Source: OSV.dev
CVE-2024-53425
PYSEC-2024-295
Nov 21, 2024
6.2
/ 10
Medium
Local
Low
None
None
Unchanged
None
None
High
A heap-buffer-overflow vulnerability was discovered in the SkipSpacesAndLineEnd function in Assimp v5.4.3. This issue occurs when processing certain malformed MD5 model files, leading to an out-of-bounds read and potential application crash. Affected versions
0.1
3.3
4.1.1
4.1.2
4.1.3
4.1.4
5.2.5
References Updated May 21, 2026 · Source: OSV.dev
CVE-2024-48426
PYSEC-2024-294
Oct 24, 2024
6.2
/ 10
Medium
Local
Low
None
None
Unchanged
None
None
High
A segmentation fault (SEGV) was detected in the SortByPTypeProcess::Execute function in the Assimp library during fuzz testing with AddressSanitizer. The crash occurred due to a read access to an invalid memory address (0x1000c9714971). Affected versions
0.1
3.3
4.1.1
4.1.2
4.1.3
4.1.4
5.2.5
References Updated May 21, 2026 · Source: OSV.dev
CVE-2024-48425
PYSEC-2024-293
Oct 24, 2024
5.5
/ 10
Medium
Local
Low
Low
None
Unchanged
None
None
High
A segmentation fault (SEGV) was detected in the Assimp::SplitLargeMeshesProcess_Triangle::UpdateNode function within the Assimp library during fuzz testing using AddressSanitizer. The crash occurs due to a read access violation at address 0x000000000460, which points to the zero page, indicating a null or invalid pointer dereference. Affected versions
0.1
3.3
4.1.1
4.1.2
4.1.3
4.1.4
5.2.5
References Updated May 21, 2026 · Source: OSV.dev
CVE-2024-48424
PYSEC-2024-292
Oct 24, 2024
5.5
/ 10
Medium
Local
Low
Low
None
Unchanged
None
None
High
A heap-buffer-overflow vulnerability has been identified in the OpenDDLParser::parseStructure function within the Assimp library, specifically during the processing of OpenGEX files. Affected versions
0.1
3.3
4.1.1
4.1.2
4.1.3
4.1.4
5.2.5
References Updated May 21, 2026 · Source: OSV.dev
CVE-2024-48423
PYSEC-2024-120
Oct 24, 2024
7.8
/ 10
High
Local
Low
Low
None
Unchanged
High
High
High
An issue in assimp v.5.4.3 allows a local attacker to execute arbitrary code via the CallbackToLogRedirector function within the Assimp library. Affected versions
0.1
3.3
4.1.1
4.1.2
4.1.3
4.1.4
5.2.5
References Updated Nov 05, 2024 · Source: OSV.dev
CVE-2024-46632
PYSEC-2024-291
Sep 26, 2024
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
None
Low
Assimp v5.4.3 is vulnerable to Buffer Overflow via the MD5Importer::LoadMD5MeshFile function. Affected versions
0.1
3.3
4.1.1
4.1.2
4.1.3
4.1.4
5.2.5
References Updated May 21, 2026 · Source: OSV.dev | ||
4.1.2
patch
33 CVEs
CVE-2025-11277
PYSEC-2025-157
Oct 05, 2025
7.8
/ 10
High
Local
Low
Low
None
Unchanged
High
High
High
A weakness has been identified in Open Asset Import Library Assimp 6.0.2. This affects the function Q3DImporter::InternReadFile of the file assimp/code/AssetLib/Q3D/Q3DLoader.cpp. Executing a manipulation can lead to heap-based buffer overflow. The attack needs to be launched locally. The exploit has been made available to the public and could be used for attacks. Affected versions
0.1
3.3
4.1.1
4.1.2
4.1.3
4.1.4
5.2.5
References Updated May 21, 2026 · Source: OSV.dev
CVE-2025-11275
PYSEC-2025-156
Oct 05, 2025
7.8
/ 10
High
Local
Low
Low
None
Unchanged
High
High
High
A vulnerability was identified in Open Asset Import Library Assimp 6.0.2. Affected by this vulnerability is the function ODDLParser::getNextSeparator in the library assimp/contrib/openddlparser/include/openddlparser/OpenDDLParserUtils.h. Such manipulation leads to heap-based buffer overflow. The attack must be carried out locally. The exploit is publicly available and might be used. Affected versions
0.1
3.3
4.1.1
4.1.2
4.1.3
4.1.4
5.2.5
References Updated May 21, 2026 · Source: OSV.dev
CVE-2025-11274
PYSEC-2025-155
Oct 05, 2025
5.5
/ 10
Medium
Local
Low
Low
None
Unchanged
None
None
High
A vulnerability was determined in Open Asset Import Library Assimp 6.0.2. Affected is the function Q3DImporter::InternReadFile of the file assimp/code/AssetLib/Q3D/Q3DLoader.cpp. This manipulation causes allocation of resources. The attack is restricted to local execution. The exploit has been publicly disclosed and may be utilized. Affected versions
0.1
3.3
4.1.1
4.1.2
4.1.3
4.1.4
5.2.5
References Updated May 21, 2026 · Source: OSV.dev
CVE-2025-5169
PYSEC-2025-176
May 26, 2025
5.5
/ 10
Medium
Local
Low
Low
None
Unchanged
None
None
High
A vulnerability classified as problematic has been found in Open Asset Import Library Assimp 5.4.3. This affects the function MDLImporter::InternReadFile_3DGS_MDL345 of the file assimp/code/AssetLib/MDL/MDLLoader.cpp. The manipulation leads to out-of-bounds read. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used. The project decided to collect all Fuzzer bugs in a main-issue to address them in the future. Affected versions
0.1
3.3
4.1.1
4.1.2
4.1.3
4.1.4
5.2.5
References Updated May 21, 2026 · Source: OSV.dev
CVE-2025-5168
PYSEC-2025-175
May 26, 2025
5.5
/ 10
Medium
Local
Low
Low
None
Unchanged
None
None
High
A vulnerability was found in Open Asset Import Library Assimp 5.4.3. It has been rated as problematic. Affected by this issue is the function MDLImporter::ImportUVCoordinate_3DGS_MDL345 of the file assimp/code/AssetLib/MDL/MDLLoader.cpp. The manipulation of the argument iIndex leads to out-of-bounds read. An attack has to be approached locally. The exploit has been disclosed to the public and may be used. The project decided to collect all Fuzzer bugs in a main-issue to address them in the future. Affected versions
0.1
3.3
4.1.1
4.1.2
4.1.3
4.1.4
5.2.5
References Updated May 21, 2026 · Source: OSV.dev
CVE-2025-5167
PYSEC-2025-174
May 26, 2025
5.5
/ 10
Medium
Local
Low
Low
None
Unchanged
None
None
High
A vulnerability was found in Open Asset Import Library Assimp 5.4.3. It has been declared as problematic. Affected by this vulnerability is the function LWOImporter::GetS0 in the library assimp/code/AssetLib/LWO/LWOLoader.h. The manipulation of the argument out leads to out-of-bounds read. The attack needs to be approached locally. The exploit has been disclosed to the public and may be used. The project decided to collect all Fuzzer bugs in a main-issue to address them in the future. Affected versions
0.1
3.3
4.1.1
4.1.2
4.1.3
4.1.4
5.2.5
References Updated May 21, 2026 · Source: OSV.dev
CVE-2025-5166
PYSEC-2025-173
May 26, 2025
5.5
/ 10
Medium
Local
Low
Low
None
Unchanged
None
None
High
A vulnerability was found in Open Asset Import Library Assimp 5.4.3. It has been classified as problematic. Affected is the function MDCImporter::InternReadFile of the file assimp/code/AssetLib/MDC/MDCLoader.cpp of the component MDC File Parser. The manipulation of the argument pcVerts leads to out-of-bounds read. It is possible to launch the attack on the local host. The exploit has been disclosed to the public and may be used. The project decided to collect all Fuzzer bugs in a main-issue to address them in the future. Affected versions
0.1
3.3
4.1.1
4.1.2
4.1.3
4.1.4
5.2.5
References Updated May 21, 2026 · Source: OSV.dev
CVE-2025-5165
PYSEC-2025-172
May 26, 2025
5.5
/ 10
Medium
Local
Low
Low
None
Unchanged
None
None
High
A vulnerability was found in Open Asset Import Library Assimp 5.4.3 and classified as problematic. This issue affects the function MDCImporter::ValidateSurfaceHeader of the file assimp/code/AssetLib/MDC/MDCLoader.cpp. The manipulation of the argument pcSurface2 leads to out-of-bounds read. Attacking locally is a requirement. The exploit has been disclosed to the public and may be used. The project decided to collect all Fuzzer bugs in a main-issue to address them in the future. Affected versions
0.1
3.3
4.1.1
4.1.2
4.1.3
4.1.4
5.2.5
References Updated May 21, 2026 · Source: OSV.dev
CVE-2025-3549
PYSEC-2025-171
Apr 14, 2025
3.3
/ 10
Low
Local
Low
Low
None
Unchanged
None
None
Low
A vulnerability, which was classified as critical, was found in Open Asset Import Library Assimp 5.4.3. Affected is the function Assimp::MD3Importer::ValidateSurfaceHeaderOffsets of the file code/AssetLib/MD3/MD3Loader.cpp of the component File Handler. The manipulation leads to heap-based buffer overflow. The attack needs to be approached locally. The exploit has been disclosed to the public and may be used. Affected versions
0.1
3.3
4.1.1
4.1.2
4.1.3
4.1.4
5.2.5
References Updated May 21, 2026 · Source: OSV.dev
CVE-2025-3196
PYSEC-2025-170
Apr 04, 2025
5.5
/ 10
Medium
Local
Low
Low
None
Unchanged
None
None
High
A vulnerability, which was classified as critical, was found in Open Asset Import Library Assimp 5.4.3. Affected is the function Assimp::MD2Importer::InternReadFile in the library code/AssetLib/MD2/MD2Loader.cpp of the component Malformed File Handler. The manipulation of the argument Name leads to stack-based buffer overflow. The attack needs to be approached locally. The exploit has been disclosed to the public and may be used. It is recommended to upgrade the affected component. Affected versions
0.1
3.3
4.1.1
4.1.2
4.1.3
4.1.4
5.2.5
References Updated May 21, 2026 · Source: OSV.dev
CVE-2025-3160
PYSEC-2025-264
Apr 03, 2025
3.3
/ 10
Low
Local
Low
None
Required
Unchanged
Low
None
None
A vulnerability has been found in Open Asset Import Library Assimp 5.4.3 and classified as problematic. This vulnerability affects the function Assimp::SceneCombiner::AddNodeHashes of the file code/Common/SceneCombiner.cpp of the component File Handler. The manipulation leads to out-of-bounds read. An attack has to be approached locally. The exploit has been disclosed to the public and may be used. The patch is identified as a0993658f40d8e13ff5823990c30b43c82a5daf0. It is recommended to apply a patch to fix this issue. Affected versions
0.1
3.3
4.1.1
4.1.2
4.1.3
4.1.4
5.2.5
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-3159
PYSEC-2025-263
Apr 03, 2025
7.8
/ 10
High
Local
Low
None
Required
Unchanged
High
High
High
A vulnerability, which was classified as critical, was found in Open Asset Import Library Assimp 5.4.3. This affects the function Assimp::ASE::Parser::ParseLV4MeshBonesVertices of the file code/AssetLib/ASE/ASEParser.cpp of the component ASE File Handler. The manipulation leads to heap-based buffer overflow. The attack needs to be approached locally. The exploit has been disclosed to the public and may be used. The identifier of the patch is e8a6286542924e628e02749c4f5ac4f91fdae71b. It is recommended to apply a patch to fix this issue. Affected versions
0.1
3.3
4.1.1
4.1.2
4.1.3
4.1.4
5.2.5
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-3158
PYSEC-2025-169
Apr 03, 2025
7.8
/ 10
High
Local
Low
None
Required
Unchanged
High
High
High
A vulnerability, which was classified as critical, has been found in Open Asset Import Library Assimp 5.4.3. Affected by this issue is the function Assimp::LWO::AnimResolver::UpdateAnimRangeSetup of the file code/AssetLib/LWO/LWOAnimation.cpp of the component LWO File Handler. The manipulation leads to heap-based buffer overflow. It is possible to launch the attack on the local host. The exploit has been disclosed to the public and may be used. Affected versions
0.1
3.3
4.1.1
4.1.2
4.1.3
4.1.4
5.2.5
References Updated May 21, 2026 · Source: OSV.dev
CVE-2025-3016
PYSEC-2025-262
Mar 31, 2025
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
None
High
A vulnerability classified as problematic was found in Open Asset Import Library Assimp 5.4.3. This vulnerability affects the function Assimp::MDLImporter::ParseTextureColorData of the file code/AssetLib/MDL/MDLMaterialLoader.cpp of the component MDL File Handler. The manipulation of the argument mWidth/mHeight leads to resource consumption. The attack can be initiated remotely. Upgrading to version 6.0 is able to address this issue. The name of the patch is 5d2a7482312db2e866439a8c05a07ce1e718bed1. It is recommended to apply a patch to fix this issue. Affected versions
0.1
3.3
4.1.1
4.1.2
4.1.3
4.1.4
5.2.5
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-3015
PYSEC-2025-261
Mar 31, 2025
8.8
/ 10
High
Network
Low
None
Required
Unchanged
High
High
High
A vulnerability classified as critical has been found in Open Asset Import Library Assimp 5.4.3. This affects the function Assimp::ASEImporter::BuildUniqueRepresentation of the file code/AssetLib/ASE/ASELoader.cpp of the component ASE File Handler. The manipulation of the argument mIndices leads to out-of-bounds read. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 6.0 is able to address this issue. The patch is named 7c705fde418d68cca4e8eff56be01b2617b0d6fe. It is recommended to apply a patch to fix this issue. Affected versions
0.1
3.3
4.1.1
4.1.2
4.1.3
4.1.4
5.2.5
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-2757
PYSEC-2025-168
Mar 25, 2025
8.8
/ 10
High
Network
Low
None
Required
Unchanged
High
High
High
A vulnerability classified as critical was found in Open Asset Import Library Assimp 5.4.3. This vulnerability affects the function AI_MD5_PARSE_STRING_IN_QUOTATION of the file code/AssetLib/MD5/MD5Parser.cpp of the component MD5 File Handler. The manipulation of the argument data leads to heap-based buffer overflow. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. Affected versions
0.1
3.3
4.1.1
4.1.2
4.1.3
4.1.4
5.2.5
References Updated May 21, 2026 · Source: OSV.dev
CVE-2025-2756
PYSEC-2025-167
Mar 25, 2025
8.8
/ 10
High
Network
Low
None
Required
Unchanged
High
High
High
A vulnerability classified as critical has been found in Open Asset Import Library Assimp 5.4.3. This affects the function Assimp::AC3DImporter::ConvertObjectSection of the file code/AssetLib/AC/ACLoader.cpp of the component AC3D File Handler. The manipulation of the argument tmp leads to heap-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. Affected versions
0.1
3.3
4.1.1
4.1.2
4.1.3
4.1.4
5.2.5
References Updated May 21, 2026 · Source: OSV.dev
CVE-2025-2755
PYSEC-2025-166
Mar 25, 2025
8.8
/ 10
High
Network
Low
None
Required
Unchanged
High
High
High
A vulnerability was found in Open Asset Import Library Assimp 5.4.3. It has been rated as critical. Affected by this issue is the function Assimp::AC3DImporter::ConvertObjectSection of the file code/AssetLib/AC/ACLoader.cpp of the component AC3D File Handler. The manipulation of the argument src.entries leads to out-of-bounds read. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. Affected versions
0.1
3.3
4.1.1
4.1.2
4.1.3
4.1.4
5.2.5
References Updated May 21, 2026 · Source: OSV.dev
CVE-2025-2754
PYSEC-2025-165
Mar 25, 2025
8.8
/ 10
High
Network
Low
None
Required
Unchanged
High
High
High
A vulnerability was found in Open Asset Import Library Assimp 5.4.3. It has been declared as critical. Affected by this vulnerability is the function Assimp::AC3DImporter::ConvertObjectSection of the file code/AssetLib/AC/ACLoader.cpp of the component AC3D File Handler. The manipulation of the argument it leads to heap-based buffer overflow. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. Affected versions
0.1
3.3
4.1.1
4.1.2
4.1.3
4.1.4
5.2.5
References Updated May 21, 2026 · Source: OSV.dev
CVE-2025-2753
PYSEC-2025-164
Mar 25, 2025
8.8
/ 10
High
Network
Low
None
Required
Unchanged
High
High
High
A vulnerability was found in Open Asset Import Library Assimp 5.4.3. It has been classified as critical. Affected is the function SceneCombiner::MergeScenes of the file code/AssetLib/LWS/LWSLoader.cpp of the component LWS File Handler. The manipulation leads to out-of-bounds read. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. Affected versions
0.1
3.3
4.1.1
4.1.2
4.1.3
4.1.4
5.2.5
References Updated May 21, 2026 · Source: OSV.dev
CVE-2025-2752
PYSEC-2025-163
Mar 25, 2025
8.8
/ 10
High
Network
Low
None
Required
Unchanged
High
High
High
A vulnerability was found in Open Asset Import Library Assimp 5.4.3 and classified as problematic. This issue affects the function fast_atoreal_move in the library include/assimp/fast_atof.h of the component CSM File Handler. The manipulation leads to out-of-bounds read. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. Affected versions
0.1
3.3
4.1.1
4.1.2
4.1.3
4.1.4
5.2.5
References Updated May 21, 2026 · Source: OSV.dev
CVE-2025-2751
PYSEC-2025-162
Mar 25, 2025
8.8
/ 10
High
Network
Low
None
Required
Unchanged
High
High
High
A vulnerability has been found in Open Asset Import Library Assimp 5.4.3 and classified as problematic. This vulnerability affects the function Assimp::CSMImporter::InternReadFile of the file code/AssetLib/CSM/CSMLoader.cpp of the component CSM File Handler. The manipulation of the argument na leads to out-of-bounds read. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. Affected versions
0.1
3.3
4.1.1
4.1.2
4.1.3
4.1.4
5.2.5
References Updated May 21, 2026 · Source: OSV.dev
CVE-2025-2750
PYSEC-2025-161
Mar 25, 2025
8.8
/ 10
High
Network
Low
None
Required
Unchanged
High
High
High
A vulnerability, which was classified as critical, was found in Open Asset Import Library Assimp 5.4.3. This affects the function Assimp::CSMImporter::InternReadFile of the file code/AssetLib/CSM/CSMLoader.cpp of the component CSM File Handler. The manipulation leads to out-of-bounds write. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. Affected versions
0.1
3.3
4.1.1
4.1.2
4.1.3
4.1.4
5.2.5
References Updated May 21, 2026 · Source: OSV.dev
CVE-2025-2592
PYSEC-2025-260
Mar 21, 2025
8.8
/ 10
High
Network
Low
None
Required
Unchanged
High
High
High
A vulnerability, which was classified as critical, has been found in Open Asset Import Library Assimp 5.4.3. This issue affects the function CSMImporter::InternReadFile of the file code/AssetLib/CSM/CSMLoader.cpp. The manipulation leads to heap-based buffer overflow. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The patch is named 2690e354da0c681db000cfd892a55226788f2743. It is recommended to apply a patch to fix this issue. Affected versions
0.1
3.3
4.1.1
4.1.2
4.1.3
4.1.4
5.2.5
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-2591
PYSEC-2025-160
Mar 21, 2025
5.5
/ 10
Medium
Local
Low
None
Required
Unchanged
None
None
High
A vulnerability classified as problematic was found in Open Asset Import Library Assimp 5.4.3. This vulnerability affects the function MDLImporter::InternReadFile_Quake1 of the file code/AssetLib/MDL/MDLLoader.cpp. The manipulation of the argument skinwidth/skinheight leads to divide by zero. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The patch is identified as ab66a1674fcfac87aaba4c8b900b315ebc3e7dbd. It is recommended to apply a patch to fix this issue. Affected versions
0.1
3.3
4.1.1
4.1.2
4.1.3
4.1.4
5.2.5
References Updated May 21, 2026 · Source: OSV.dev
CVE-2025-2152
PYSEC-2025-159
Mar 10, 2025
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
A vulnerability, which was classified as critical, has been found in Open Asset Import Library Assimp 5.4.3. This issue affects the function Assimp::BaseImporter::ConvertToUTF8 of the file BaseImporter.cpp of the component File Handler. The manipulation leads to heap-based buffer overflow. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. Affected versions
0.1
3.3
4.1.1
4.1.2
4.1.3
4.1.4
5.2.5
References Updated May 21, 2026 · Source: OSV.dev
CVE-2025-2151
PYSEC-2025-158
Mar 10, 2025
8.8
/ 10
High
Network
Low
None
Required
Unchanged
High
High
High
A vulnerability classified as critical was found in Open Asset Import Library Assimp 5.4.3. This vulnerability affects the function Assimp::GetNextLine in the library ParsingUtils.h of the component File Handler. The manipulation leads to stack-based buffer overflow. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. Affected versions
0.1
3.3
4.1.1
4.1.2
4.1.3
4.1.4
5.2.5
References Updated May 21, 2026 · Source: OSV.dev
CVE-2024-53425
PYSEC-2024-295
Nov 21, 2024
6.2
/ 10
Medium
Local
Low
None
None
Unchanged
None
None
High
A heap-buffer-overflow vulnerability was discovered in the SkipSpacesAndLineEnd function in Assimp v5.4.3. This issue occurs when processing certain malformed MD5 model files, leading to an out-of-bounds read and potential application crash. Affected versions
0.1
3.3
4.1.1
4.1.2
4.1.3
4.1.4
5.2.5
References Updated May 21, 2026 · Source: OSV.dev
CVE-2024-48426
PYSEC-2024-294
Oct 24, 2024
6.2
/ 10
Medium
Local
Low
None
None
Unchanged
None
None
High
A segmentation fault (SEGV) was detected in the SortByPTypeProcess::Execute function in the Assimp library during fuzz testing with AddressSanitizer. The crash occurred due to a read access to an invalid memory address (0x1000c9714971). Affected versions
0.1
3.3
4.1.1
4.1.2
4.1.3
4.1.4
5.2.5
References Updated May 21, 2026 · Source: OSV.dev
CVE-2024-48425
PYSEC-2024-293
Oct 24, 2024
5.5
/ 10
Medium
Local
Low
Low
None
Unchanged
None
None
High
A segmentation fault (SEGV) was detected in the Assimp::SplitLargeMeshesProcess_Triangle::UpdateNode function within the Assimp library during fuzz testing using AddressSanitizer. The crash occurs due to a read access violation at address 0x000000000460, which points to the zero page, indicating a null or invalid pointer dereference. Affected versions
0.1
3.3
4.1.1
4.1.2
4.1.3
4.1.4
5.2.5
References Updated May 21, 2026 · Source: OSV.dev
CVE-2024-48424
PYSEC-2024-292
Oct 24, 2024
5.5
/ 10
Medium
Local
Low
Low
None
Unchanged
None
None
High
A heap-buffer-overflow vulnerability has been identified in the OpenDDLParser::parseStructure function within the Assimp library, specifically during the processing of OpenGEX files. Affected versions
0.1
3.3
4.1.1
4.1.2
4.1.3
4.1.4
5.2.5
References Updated May 21, 2026 · Source: OSV.dev
CVE-2024-48423
PYSEC-2024-120
Oct 24, 2024
7.8
/ 10
High
Local
Low
Low
None
Unchanged
High
High
High
An issue in assimp v.5.4.3 allows a local attacker to execute arbitrary code via the CallbackToLogRedirector function within the Assimp library. Affected versions
0.1
3.3
4.1.1
4.1.2
4.1.3
4.1.4
5.2.5
References Updated Nov 05, 2024 · Source: OSV.dev
CVE-2024-46632
PYSEC-2024-291
Sep 26, 2024
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
None
Low
Assimp v5.4.3 is vulnerable to Buffer Overflow via the MD5Importer::LoadMD5MeshFile function. Affected versions
0.1
3.3
4.1.1
4.1.2
4.1.3
4.1.4
5.2.5
References Updated May 21, 2026 · Source: OSV.dev | ||
4.1.1
major
33 CVEs
CVE-2025-11277
PYSEC-2025-157
Oct 05, 2025
7.8
/ 10
High
Local
Low
Low
None
Unchanged
High
High
High
A weakness has been identified in Open Asset Import Library Assimp 6.0.2. This affects the function Q3DImporter::InternReadFile of the file assimp/code/AssetLib/Q3D/Q3DLoader.cpp. Executing a manipulation can lead to heap-based buffer overflow. The attack needs to be launched locally. The exploit has been made available to the public and could be used for attacks. Affected versions
0.1
3.3
4.1.1
4.1.2
4.1.3
4.1.4
5.2.5
References Updated May 21, 2026 · Source: OSV.dev
CVE-2025-11275
PYSEC-2025-156
Oct 05, 2025
7.8
/ 10
High
Local
Low
Low
None
Unchanged
High
High
High
A vulnerability was identified in Open Asset Import Library Assimp 6.0.2. Affected by this vulnerability is the function ODDLParser::getNextSeparator in the library assimp/contrib/openddlparser/include/openddlparser/OpenDDLParserUtils.h. Such manipulation leads to heap-based buffer overflow. The attack must be carried out locally. The exploit is publicly available and might be used. Affected versions
0.1
3.3
4.1.1
4.1.2
4.1.3
4.1.4
5.2.5
References Updated May 21, 2026 · Source: OSV.dev
CVE-2025-11274
PYSEC-2025-155
Oct 05, 2025
5.5
/ 10
Medium
Local
Low
Low
None
Unchanged
None
None
High
A vulnerability was determined in Open Asset Import Library Assimp 6.0.2. Affected is the function Q3DImporter::InternReadFile of the file assimp/code/AssetLib/Q3D/Q3DLoader.cpp. This manipulation causes allocation of resources. The attack is restricted to local execution. The exploit has been publicly disclosed and may be utilized. Affected versions
0.1
3.3
4.1.1
4.1.2
4.1.3
4.1.4
5.2.5
References Updated May 21, 2026 · Source: OSV.dev
CVE-2025-5169
PYSEC-2025-176
May 26, 2025
5.5
/ 10
Medium
Local
Low
Low
None
Unchanged
None
None
High
A vulnerability classified as problematic has been found in Open Asset Import Library Assimp 5.4.3. This affects the function MDLImporter::InternReadFile_3DGS_MDL345 of the file assimp/code/AssetLib/MDL/MDLLoader.cpp. The manipulation leads to out-of-bounds read. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used. The project decided to collect all Fuzzer bugs in a main-issue to address them in the future. Affected versions
0.1
3.3
4.1.1
4.1.2
4.1.3
4.1.4
5.2.5
References Updated May 21, 2026 · Source: OSV.dev
CVE-2025-5168
PYSEC-2025-175
May 26, 2025
5.5
/ 10
Medium
Local
Low
Low
None
Unchanged
None
None
High
A vulnerability was found in Open Asset Import Library Assimp 5.4.3. It has been rated as problematic. Affected by this issue is the function MDLImporter::ImportUVCoordinate_3DGS_MDL345 of the file assimp/code/AssetLib/MDL/MDLLoader.cpp. The manipulation of the argument iIndex leads to out-of-bounds read. An attack has to be approached locally. The exploit has been disclosed to the public and may be used. The project decided to collect all Fuzzer bugs in a main-issue to address them in the future. Affected versions
0.1
3.3
4.1.1
4.1.2
4.1.3
4.1.4
5.2.5
References Updated May 21, 2026 · Source: OSV.dev
CVE-2025-5167
PYSEC-2025-174
May 26, 2025
5.5
/ 10
Medium
Local
Low
Low
None
Unchanged
None
None
High
A vulnerability was found in Open Asset Import Library Assimp 5.4.3. It has been declared as problematic. Affected by this vulnerability is the function LWOImporter::GetS0 in the library assimp/code/AssetLib/LWO/LWOLoader.h. The manipulation of the argument out leads to out-of-bounds read. The attack needs to be approached locally. The exploit has been disclosed to the public and may be used. The project decided to collect all Fuzzer bugs in a main-issue to address them in the future. Affected versions
0.1
3.3
4.1.1
4.1.2
4.1.3
4.1.4
5.2.5
References Updated May 21, 2026 · Source: OSV.dev
CVE-2025-5166
PYSEC-2025-173
May 26, 2025
5.5
/ 10
Medium
Local
Low
Low
None
Unchanged
None
None
High
A vulnerability was found in Open Asset Import Library Assimp 5.4.3. It has been classified as problematic. Affected is the function MDCImporter::InternReadFile of the file assimp/code/AssetLib/MDC/MDCLoader.cpp of the component MDC File Parser. The manipulation of the argument pcVerts leads to out-of-bounds read. It is possible to launch the attack on the local host. The exploit has been disclosed to the public and may be used. The project decided to collect all Fuzzer bugs in a main-issue to address them in the future. Affected versions
0.1
3.3
4.1.1
4.1.2
4.1.3
4.1.4
5.2.5
References Updated May 21, 2026 · Source: OSV.dev
CVE-2025-5165
PYSEC-2025-172
May 26, 2025
5.5
/ 10
Medium
Local
Low
Low
None
Unchanged
None
None
High
A vulnerability was found in Open Asset Import Library Assimp 5.4.3 and classified as problematic. This issue affects the function MDCImporter::ValidateSurfaceHeader of the file assimp/code/AssetLib/MDC/MDCLoader.cpp. The manipulation of the argument pcSurface2 leads to out-of-bounds read. Attacking locally is a requirement. The exploit has been disclosed to the public and may be used. The project decided to collect all Fuzzer bugs in a main-issue to address them in the future. Affected versions
0.1
3.3
4.1.1
4.1.2
4.1.3
4.1.4
5.2.5
References Updated May 21, 2026 · Source: OSV.dev
CVE-2025-3549
PYSEC-2025-171
Apr 14, 2025
3.3
/ 10
Low
Local
Low
Low
None
Unchanged
None
None
Low
A vulnerability, which was classified as critical, was found in Open Asset Import Library Assimp 5.4.3. Affected is the function Assimp::MD3Importer::ValidateSurfaceHeaderOffsets of the file code/AssetLib/MD3/MD3Loader.cpp of the component File Handler. The manipulation leads to heap-based buffer overflow. The attack needs to be approached locally. The exploit has been disclosed to the public and may be used. Affected versions
0.1
3.3
4.1.1
4.1.2
4.1.3
4.1.4
5.2.5
References Updated May 21, 2026 · Source: OSV.dev
CVE-2025-3196
PYSEC-2025-170
Apr 04, 2025
5.5
/ 10
Medium
Local
Low
Low
None
Unchanged
None
None
High
A vulnerability, which was classified as critical, was found in Open Asset Import Library Assimp 5.4.3. Affected is the function Assimp::MD2Importer::InternReadFile in the library code/AssetLib/MD2/MD2Loader.cpp of the component Malformed File Handler. The manipulation of the argument Name leads to stack-based buffer overflow. The attack needs to be approached locally. The exploit has been disclosed to the public and may be used. It is recommended to upgrade the affected component. Affected versions
0.1
3.3
4.1.1
4.1.2
4.1.3
4.1.4
5.2.5
References Updated May 21, 2026 · Source: OSV.dev
CVE-2025-3160
PYSEC-2025-264
Apr 03, 2025
3.3
/ 10
Low
Local
Low
None
Required
Unchanged
Low
None
None
A vulnerability has been found in Open Asset Import Library Assimp 5.4.3 and classified as problematic. This vulnerability affects the function Assimp::SceneCombiner::AddNodeHashes of the file code/Common/SceneCombiner.cpp of the component File Handler. The manipulation leads to out-of-bounds read. An attack has to be approached locally. The exploit has been disclosed to the public and may be used. The patch is identified as a0993658f40d8e13ff5823990c30b43c82a5daf0. It is recommended to apply a patch to fix this issue. Affected versions
0.1
3.3
4.1.1
4.1.2
4.1.3
4.1.4
5.2.5
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-3159
PYSEC-2025-263
Apr 03, 2025
7.8
/ 10
High
Local
Low
None
Required
Unchanged
High
High
High
A vulnerability, which was classified as critical, was found in Open Asset Import Library Assimp 5.4.3. This affects the function Assimp::ASE::Parser::ParseLV4MeshBonesVertices of the file code/AssetLib/ASE/ASEParser.cpp of the component ASE File Handler. The manipulation leads to heap-based buffer overflow. The attack needs to be approached locally. The exploit has been disclosed to the public and may be used. The identifier of the patch is e8a6286542924e628e02749c4f5ac4f91fdae71b. It is recommended to apply a patch to fix this issue. Affected versions
0.1
3.3
4.1.1
4.1.2
4.1.3
4.1.4
5.2.5
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-3158
PYSEC-2025-169
Apr 03, 2025
7.8
/ 10
High
Local
Low
None
Required
Unchanged
High
High
High
A vulnerability, which was classified as critical, has been found in Open Asset Import Library Assimp 5.4.3. Affected by this issue is the function Assimp::LWO::AnimResolver::UpdateAnimRangeSetup of the file code/AssetLib/LWO/LWOAnimation.cpp of the component LWO File Handler. The manipulation leads to heap-based buffer overflow. It is possible to launch the attack on the local host. The exploit has been disclosed to the public and may be used. Affected versions
0.1
3.3
4.1.1
4.1.2
4.1.3
4.1.4
5.2.5
References Updated May 21, 2026 · Source: OSV.dev
CVE-2025-3016
PYSEC-2025-262
Mar 31, 2025
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
None
High
A vulnerability classified as problematic was found in Open Asset Import Library Assimp 5.4.3. This vulnerability affects the function Assimp::MDLImporter::ParseTextureColorData of the file code/AssetLib/MDL/MDLMaterialLoader.cpp of the component MDL File Handler. The manipulation of the argument mWidth/mHeight leads to resource consumption. The attack can be initiated remotely. Upgrading to version 6.0 is able to address this issue. The name of the patch is 5d2a7482312db2e866439a8c05a07ce1e718bed1. It is recommended to apply a patch to fix this issue. Affected versions
0.1
3.3
4.1.1
4.1.2
4.1.3
4.1.4
5.2.5
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-3015
PYSEC-2025-261
Mar 31, 2025
8.8
/ 10
High
Network
Low
None
Required
Unchanged
High
High
High
A vulnerability classified as critical has been found in Open Asset Import Library Assimp 5.4.3. This affects the function Assimp::ASEImporter::BuildUniqueRepresentation of the file code/AssetLib/ASE/ASELoader.cpp of the component ASE File Handler. The manipulation of the argument mIndices leads to out-of-bounds read. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 6.0 is able to address this issue. The patch is named 7c705fde418d68cca4e8eff56be01b2617b0d6fe. It is recommended to apply a patch to fix this issue. Affected versions
0.1
3.3
4.1.1
4.1.2
4.1.3
4.1.4
5.2.5
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-2757
PYSEC-2025-168
Mar 25, 2025
8.8
/ 10
High
Network
Low
None
Required
Unchanged
High
High
High
A vulnerability classified as critical was found in Open Asset Import Library Assimp 5.4.3. This vulnerability affects the function AI_MD5_PARSE_STRING_IN_QUOTATION of the file code/AssetLib/MD5/MD5Parser.cpp of the component MD5 File Handler. The manipulation of the argument data leads to heap-based buffer overflow. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. Affected versions
0.1
3.3
4.1.1
4.1.2
4.1.3
4.1.4
5.2.5
References Updated May 21, 2026 · Source: OSV.dev
CVE-2025-2756
PYSEC-2025-167
Mar 25, 2025
8.8
/ 10
High
Network
Low
None
Required
Unchanged
High
High
High
A vulnerability classified as critical has been found in Open Asset Import Library Assimp 5.4.3. This affects the function Assimp::AC3DImporter::ConvertObjectSection of the file code/AssetLib/AC/ACLoader.cpp of the component AC3D File Handler. The manipulation of the argument tmp leads to heap-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. Affected versions
0.1
3.3
4.1.1
4.1.2
4.1.3
4.1.4
5.2.5
References Updated May 21, 2026 · Source: OSV.dev
CVE-2025-2755
PYSEC-2025-166
Mar 25, 2025
8.8
/ 10
High
Network
Low
None
Required
Unchanged
High
High
High
A vulnerability was found in Open Asset Import Library Assimp 5.4.3. It has been rated as critical. Affected by this issue is the function Assimp::AC3DImporter::ConvertObjectSection of the file code/AssetLib/AC/ACLoader.cpp of the component AC3D File Handler. The manipulation of the argument src.entries leads to out-of-bounds read. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. Affected versions
0.1
3.3
4.1.1
4.1.2
4.1.3
4.1.4
5.2.5
References Updated May 21, 2026 · Source: OSV.dev
CVE-2025-2754
PYSEC-2025-165
Mar 25, 2025
8.8
/ 10
High
Network
Low
None
Required
Unchanged
High
High
High
A vulnerability was found in Open Asset Import Library Assimp 5.4.3. It has been declared as critical. Affected by this vulnerability is the function Assimp::AC3DImporter::ConvertObjectSection of the file code/AssetLib/AC/ACLoader.cpp of the component AC3D File Handler. The manipulation of the argument it leads to heap-based buffer overflow. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. Affected versions
0.1
3.3
4.1.1
4.1.2
4.1.3
4.1.4
5.2.5
References Updated May 21, 2026 · Source: OSV.dev
CVE-2025-2753
PYSEC-2025-164
Mar 25, 2025
8.8
/ 10
High
Network
Low
None
Required
Unchanged
High
High
High
A vulnerability was found in Open Asset Import Library Assimp 5.4.3. It has been classified as critical. Affected is the function SceneCombiner::MergeScenes of the file code/AssetLib/LWS/LWSLoader.cpp of the component LWS File Handler. The manipulation leads to out-of-bounds read. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. Affected versions
0.1
3.3
4.1.1
4.1.2
4.1.3
4.1.4
5.2.5
References Updated May 21, 2026 · Source: OSV.dev
CVE-2025-2752
PYSEC-2025-163
Mar 25, 2025
8.8
/ 10
High
Network
Low
None
Required
Unchanged
High
High
High
A vulnerability was found in Open Asset Import Library Assimp 5.4.3 and classified as problematic. This issue affects the function fast_atoreal_move in the library include/assimp/fast_atof.h of the component CSM File Handler. The manipulation leads to out-of-bounds read. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. Affected versions
0.1
3.3
4.1.1
4.1.2
4.1.3
4.1.4
5.2.5
References Updated May 21, 2026 · Source: OSV.dev
CVE-2025-2751
PYSEC-2025-162
Mar 25, 2025
8.8
/ 10
High
Network
Low
None
Required
Unchanged
High
High
High
A vulnerability has been found in Open Asset Import Library Assimp 5.4.3 and classified as problematic. This vulnerability affects the function Assimp::CSMImporter::InternReadFile of the file code/AssetLib/CSM/CSMLoader.cpp of the component CSM File Handler. The manipulation of the argument na leads to out-of-bounds read. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. Affected versions
0.1
3.3
4.1.1
4.1.2
4.1.3
4.1.4
5.2.5
References Updated May 21, 2026 · Source: OSV.dev
CVE-2025-2750
PYSEC-2025-161
Mar 25, 2025
8.8
/ 10
High
Network
Low
None
Required
Unchanged
High
High
High
A vulnerability, which was classified as critical, was found in Open Asset Import Library Assimp 5.4.3. This affects the function Assimp::CSMImporter::InternReadFile of the file code/AssetLib/CSM/CSMLoader.cpp of the component CSM File Handler. The manipulation leads to out-of-bounds write. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. Affected versions
0.1
3.3
4.1.1
4.1.2
4.1.3
4.1.4
5.2.5
References Updated May 21, 2026 · Source: OSV.dev
CVE-2025-2592
PYSEC-2025-260
Mar 21, 2025
8.8
/ 10
High
Network
Low
None
Required
Unchanged
High
High
High
A vulnerability, which was classified as critical, has been found in Open Asset Import Library Assimp 5.4.3. This issue affects the function CSMImporter::InternReadFile of the file code/AssetLib/CSM/CSMLoader.cpp. The manipulation leads to heap-based buffer overflow. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The patch is named 2690e354da0c681db000cfd892a55226788f2743. It is recommended to apply a patch to fix this issue. Affected versions
0.1
3.3
4.1.1
4.1.2
4.1.3
4.1.4
5.2.5
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-2591
PYSEC-2025-160
Mar 21, 2025
5.5
/ 10
Medium
Local
Low
None
Required
Unchanged
None
None
High
A vulnerability classified as problematic was found in Open Asset Import Library Assimp 5.4.3. This vulnerability affects the function MDLImporter::InternReadFile_Quake1 of the file code/AssetLib/MDL/MDLLoader.cpp. The manipulation of the argument skinwidth/skinheight leads to divide by zero. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The patch is identified as ab66a1674fcfac87aaba4c8b900b315ebc3e7dbd. It is recommended to apply a patch to fix this issue. Affected versions
0.1
3.3
4.1.1
4.1.2
4.1.3
4.1.4
5.2.5
References Updated May 21, 2026 · Source: OSV.dev
CVE-2025-2152
PYSEC-2025-159
Mar 10, 2025
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
A vulnerability, which was classified as critical, has been found in Open Asset Import Library Assimp 5.4.3. This issue affects the function Assimp::BaseImporter::ConvertToUTF8 of the file BaseImporter.cpp of the component File Handler. The manipulation leads to heap-based buffer overflow. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. Affected versions
0.1
3.3
4.1.1
4.1.2
4.1.3
4.1.4
5.2.5
References Updated May 21, 2026 · Source: OSV.dev
CVE-2025-2151
PYSEC-2025-158
Mar 10, 2025
8.8
/ 10
High
Network
Low
None
Required
Unchanged
High
High
High
A vulnerability classified as critical was found in Open Asset Import Library Assimp 5.4.3. This vulnerability affects the function Assimp::GetNextLine in the library ParsingUtils.h of the component File Handler. The manipulation leads to stack-based buffer overflow. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. Affected versions
0.1
3.3
4.1.1
4.1.2
4.1.3
4.1.4
5.2.5
References Updated May 21, 2026 · Source: OSV.dev
CVE-2024-53425
PYSEC-2024-295
Nov 21, 2024
6.2
/ 10
Medium
Local
Low
None
None
Unchanged
None
None
High
A heap-buffer-overflow vulnerability was discovered in the SkipSpacesAndLineEnd function in Assimp v5.4.3. This issue occurs when processing certain malformed MD5 model files, leading to an out-of-bounds read and potential application crash. Affected versions
0.1
3.3
4.1.1
4.1.2
4.1.3
4.1.4
5.2.5
References Updated May 21, 2026 · Source: OSV.dev
CVE-2024-48426
PYSEC-2024-294
Oct 24, 2024
6.2
/ 10
Medium
Local
Low
None
None
Unchanged
None
None
High
A segmentation fault (SEGV) was detected in the SortByPTypeProcess::Execute function in the Assimp library during fuzz testing with AddressSanitizer. The crash occurred due to a read access to an invalid memory address (0x1000c9714971). Affected versions
0.1
3.3
4.1.1
4.1.2
4.1.3
4.1.4
5.2.5
References Updated May 21, 2026 · Source: OSV.dev
CVE-2024-48425
PYSEC-2024-293
Oct 24, 2024
5.5
/ 10
Medium
Local
Low
Low
None
Unchanged
None
None
High
A segmentation fault (SEGV) was detected in the Assimp::SplitLargeMeshesProcess_Triangle::UpdateNode function within the Assimp library during fuzz testing using AddressSanitizer. The crash occurs due to a read access violation at address 0x000000000460, which points to the zero page, indicating a null or invalid pointer dereference. Affected versions
0.1
3.3
4.1.1
4.1.2
4.1.3
4.1.4
5.2.5
References Updated May 21, 2026 · Source: OSV.dev
CVE-2024-48424
PYSEC-2024-292
Oct 24, 2024
5.5
/ 10
Medium
Local
Low
Low
None
Unchanged
None
None
High
A heap-buffer-overflow vulnerability has been identified in the OpenDDLParser::parseStructure function within the Assimp library, specifically during the processing of OpenGEX files. Affected versions
0.1
3.3
4.1.1
4.1.2
4.1.3
4.1.4
5.2.5
References Updated May 21, 2026 · Source: OSV.dev
CVE-2024-48423
PYSEC-2024-120
Oct 24, 2024
7.8
/ 10
High
Local
Low
Low
None
Unchanged
High
High
High
An issue in assimp v.5.4.3 allows a local attacker to execute arbitrary code via the CallbackToLogRedirector function within the Assimp library. Affected versions
0.1
3.3
4.1.1
4.1.2
4.1.3
4.1.4
5.2.5
References Updated Nov 05, 2024 · Source: OSV.dev
CVE-2024-46632
PYSEC-2024-291
Sep 26, 2024
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
None
Low
Assimp v5.4.3 is vulnerable to Buffer Overflow via the MD5Importer::LoadMD5MeshFile function. Affected versions
0.1
3.3
4.1.1
4.1.2
4.1.3
4.1.4
5.2.5
References Updated May 21, 2026 · Source: OSV.dev | ||
3.3
major
33 CVEs
CVE-2025-11277
PYSEC-2025-157
Oct 05, 2025
7.8
/ 10
High
Local
Low
Low
None
Unchanged
High
High
High
A weakness has been identified in Open Asset Import Library Assimp 6.0.2. This affects the function Q3DImporter::InternReadFile of the file assimp/code/AssetLib/Q3D/Q3DLoader.cpp. Executing a manipulation can lead to heap-based buffer overflow. The attack needs to be launched locally. The exploit has been made available to the public and could be used for attacks. Affected versions
0.1
3.3
4.1.1
4.1.2
4.1.3
4.1.4
5.2.5
References Updated May 21, 2026 · Source: OSV.dev
CVE-2025-11275
PYSEC-2025-156
Oct 05, 2025
7.8
/ 10
High
Local
Low
Low
None
Unchanged
High
High
High
A vulnerability was identified in Open Asset Import Library Assimp 6.0.2. Affected by this vulnerability is the function ODDLParser::getNextSeparator in the library assimp/contrib/openddlparser/include/openddlparser/OpenDDLParserUtils.h. Such manipulation leads to heap-based buffer overflow. The attack must be carried out locally. The exploit is publicly available and might be used. Affected versions
0.1
3.3
4.1.1
4.1.2
4.1.3
4.1.4
5.2.5
References Updated May 21, 2026 · Source: OSV.dev
CVE-2025-11274
PYSEC-2025-155
Oct 05, 2025
5.5
/ 10
Medium
Local
Low
Low
None
Unchanged
None
None
High
A vulnerability was determined in Open Asset Import Library Assimp 6.0.2. Affected is the function Q3DImporter::InternReadFile of the file assimp/code/AssetLib/Q3D/Q3DLoader.cpp. This manipulation causes allocation of resources. The attack is restricted to local execution. The exploit has been publicly disclosed and may be utilized. Affected versions
0.1
3.3
4.1.1
4.1.2
4.1.3
4.1.4
5.2.5
References Updated May 21, 2026 · Source: OSV.dev
CVE-2025-5169
PYSEC-2025-176
May 26, 2025
5.5
/ 10
Medium
Local
Low
Low
None
Unchanged
None
None
High
A vulnerability classified as problematic has been found in Open Asset Import Library Assimp 5.4.3. This affects the function MDLImporter::InternReadFile_3DGS_MDL345 of the file assimp/code/AssetLib/MDL/MDLLoader.cpp. The manipulation leads to out-of-bounds read. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used. The project decided to collect all Fuzzer bugs in a main-issue to address them in the future. Affected versions
0.1
3.3
4.1.1
4.1.2
4.1.3
4.1.4
5.2.5
References Updated May 21, 2026 · Source: OSV.dev
CVE-2025-5168
PYSEC-2025-175
May 26, 2025
5.5
/ 10
Medium
Local
Low
Low
None
Unchanged
None
None
High
A vulnerability was found in Open Asset Import Library Assimp 5.4.3. It has been rated as problematic. Affected by this issue is the function MDLImporter::ImportUVCoordinate_3DGS_MDL345 of the file assimp/code/AssetLib/MDL/MDLLoader.cpp. The manipulation of the argument iIndex leads to out-of-bounds read. An attack has to be approached locally. The exploit has been disclosed to the public and may be used. The project decided to collect all Fuzzer bugs in a main-issue to address them in the future. Affected versions
0.1
3.3
4.1.1
4.1.2
4.1.3
4.1.4
5.2.5
References Updated May 21, 2026 · Source: OSV.dev
CVE-2025-5167
PYSEC-2025-174
May 26, 2025
5.5
/ 10
Medium
Local
Low
Low
None
Unchanged
None
None
High
A vulnerability was found in Open Asset Import Library Assimp 5.4.3. It has been declared as problematic. Affected by this vulnerability is the function LWOImporter::GetS0 in the library assimp/code/AssetLib/LWO/LWOLoader.h. The manipulation of the argument out leads to out-of-bounds read. The attack needs to be approached locally. The exploit has been disclosed to the public and may be used. The project decided to collect all Fuzzer bugs in a main-issue to address them in the future. Affected versions
0.1
3.3
4.1.1
4.1.2
4.1.3
4.1.4
5.2.5
References Updated May 21, 2026 · Source: OSV.dev
CVE-2025-5166
PYSEC-2025-173
May 26, 2025
5.5
/ 10
Medium
Local
Low
Low
None
Unchanged
None
None
High
A vulnerability was found in Open Asset Import Library Assimp 5.4.3. It has been classified as problematic. Affected is the function MDCImporter::InternReadFile of the file assimp/code/AssetLib/MDC/MDCLoader.cpp of the component MDC File Parser. The manipulation of the argument pcVerts leads to out-of-bounds read. It is possible to launch the attack on the local host. The exploit has been disclosed to the public and may be used. The project decided to collect all Fuzzer bugs in a main-issue to address them in the future. Affected versions
0.1
3.3
4.1.1
4.1.2
4.1.3
4.1.4
5.2.5
References Updated May 21, 2026 · Source: OSV.dev
CVE-2025-5165
PYSEC-2025-172
May 26, 2025
5.5
/ 10
Medium
Local
Low
Low
None
Unchanged
None
None
High
A vulnerability was found in Open Asset Import Library Assimp 5.4.3 and classified as problematic. This issue affects the function MDCImporter::ValidateSurfaceHeader of the file assimp/code/AssetLib/MDC/MDCLoader.cpp. The manipulation of the argument pcSurface2 leads to out-of-bounds read. Attacking locally is a requirement. The exploit has been disclosed to the public and may be used. The project decided to collect all Fuzzer bugs in a main-issue to address them in the future. Affected versions
0.1
3.3
4.1.1
4.1.2
4.1.3
4.1.4
5.2.5
References Updated May 21, 2026 · Source: OSV.dev
CVE-2025-3549
PYSEC-2025-171
Apr 14, 2025
3.3
/ 10
Low
Local
Low
Low
None
Unchanged
None
None
Low
A vulnerability, which was classified as critical, was found in Open Asset Import Library Assimp 5.4.3. Affected is the function Assimp::MD3Importer::ValidateSurfaceHeaderOffsets of the file code/AssetLib/MD3/MD3Loader.cpp of the component File Handler. The manipulation leads to heap-based buffer overflow. The attack needs to be approached locally. The exploit has been disclosed to the public and may be used. Affected versions
0.1
3.3
4.1.1
4.1.2
4.1.3
4.1.4
5.2.5
References Updated May 21, 2026 · Source: OSV.dev
CVE-2025-3196
PYSEC-2025-170
Apr 04, 2025
5.5
/ 10
Medium
Local
Low
Low
None
Unchanged
None
None
High
A vulnerability, which was classified as critical, was found in Open Asset Import Library Assimp 5.4.3. Affected is the function Assimp::MD2Importer::InternReadFile in the library code/AssetLib/MD2/MD2Loader.cpp of the component Malformed File Handler. The manipulation of the argument Name leads to stack-based buffer overflow. The attack needs to be approached locally. The exploit has been disclosed to the public and may be used. It is recommended to upgrade the affected component. Affected versions
0.1
3.3
4.1.1
4.1.2
4.1.3
4.1.4
5.2.5
References Updated May 21, 2026 · Source: OSV.dev
CVE-2025-3160
PYSEC-2025-264
Apr 03, 2025
3.3
/ 10
Low
Local
Low
None
Required
Unchanged
Low
None
None
A vulnerability has been found in Open Asset Import Library Assimp 5.4.3 and classified as problematic. This vulnerability affects the function Assimp::SceneCombiner::AddNodeHashes of the file code/Common/SceneCombiner.cpp of the component File Handler. The manipulation leads to out-of-bounds read. An attack has to be approached locally. The exploit has been disclosed to the public and may be used. The patch is identified as a0993658f40d8e13ff5823990c30b43c82a5daf0. It is recommended to apply a patch to fix this issue. Affected versions
0.1
3.3
4.1.1
4.1.2
4.1.3
4.1.4
5.2.5
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-3159
PYSEC-2025-263
Apr 03, 2025
7.8
/ 10
High
Local
Low
None
Required
Unchanged
High
High
High
A vulnerability, which was classified as critical, was found in Open Asset Import Library Assimp 5.4.3. This affects the function Assimp::ASE::Parser::ParseLV4MeshBonesVertices of the file code/AssetLib/ASE/ASEParser.cpp of the component ASE File Handler. The manipulation leads to heap-based buffer overflow. The attack needs to be approached locally. The exploit has been disclosed to the public and may be used. The identifier of the patch is e8a6286542924e628e02749c4f5ac4f91fdae71b. It is recommended to apply a patch to fix this issue. Affected versions
0.1
3.3
4.1.1
4.1.2
4.1.3
4.1.4
5.2.5
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-3158
PYSEC-2025-169
Apr 03, 2025
7.8
/ 10
High
Local
Low
None
Required
Unchanged
High
High
High
A vulnerability, which was classified as critical, has been found in Open Asset Import Library Assimp 5.4.3. Affected by this issue is the function Assimp::LWO::AnimResolver::UpdateAnimRangeSetup of the file code/AssetLib/LWO/LWOAnimation.cpp of the component LWO File Handler. The manipulation leads to heap-based buffer overflow. It is possible to launch the attack on the local host. The exploit has been disclosed to the public and may be used. Affected versions
0.1
3.3
4.1.1
4.1.2
4.1.3
4.1.4
5.2.5
References Updated May 21, 2026 · Source: OSV.dev
CVE-2025-3016
PYSEC-2025-262
Mar 31, 2025
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
None
High
A vulnerability classified as problematic was found in Open Asset Import Library Assimp 5.4.3. This vulnerability affects the function Assimp::MDLImporter::ParseTextureColorData of the file code/AssetLib/MDL/MDLMaterialLoader.cpp of the component MDL File Handler. The manipulation of the argument mWidth/mHeight leads to resource consumption. The attack can be initiated remotely. Upgrading to version 6.0 is able to address this issue. The name of the patch is 5d2a7482312db2e866439a8c05a07ce1e718bed1. It is recommended to apply a patch to fix this issue. Affected versions
0.1
3.3
4.1.1
4.1.2
4.1.3
4.1.4
5.2.5
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-3015
PYSEC-2025-261
Mar 31, 2025
8.8
/ 10
High
Network
Low
None
Required
Unchanged
High
High
High
A vulnerability classified as critical has been found in Open Asset Import Library Assimp 5.4.3. This affects the function Assimp::ASEImporter::BuildUniqueRepresentation of the file code/AssetLib/ASE/ASELoader.cpp of the component ASE File Handler. The manipulation of the argument mIndices leads to out-of-bounds read. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 6.0 is able to address this issue. The patch is named 7c705fde418d68cca4e8eff56be01b2617b0d6fe. It is recommended to apply a patch to fix this issue. Affected versions
0.1
3.3
4.1.1
4.1.2
4.1.3
4.1.4
5.2.5
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-2757
PYSEC-2025-168
Mar 25, 2025
8.8
/ 10
High
Network
Low
None
Required
Unchanged
High
High
High
A vulnerability classified as critical was found in Open Asset Import Library Assimp 5.4.3. This vulnerability affects the function AI_MD5_PARSE_STRING_IN_QUOTATION of the file code/AssetLib/MD5/MD5Parser.cpp of the component MD5 File Handler. The manipulation of the argument data leads to heap-based buffer overflow. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. Affected versions
0.1
3.3
4.1.1
4.1.2
4.1.3
4.1.4
5.2.5
References Updated May 21, 2026 · Source: OSV.dev
CVE-2025-2756
PYSEC-2025-167
Mar 25, 2025
8.8
/ 10
High
Network
Low
None
Required
Unchanged
High
High
High
A vulnerability classified as critical has been found in Open Asset Import Library Assimp 5.4.3. This affects the function Assimp::AC3DImporter::ConvertObjectSection of the file code/AssetLib/AC/ACLoader.cpp of the component AC3D File Handler. The manipulation of the argument tmp leads to heap-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. Affected versions
0.1
3.3
4.1.1
4.1.2
4.1.3
4.1.4
5.2.5
References Updated May 21, 2026 · Source: OSV.dev
CVE-2025-2755
PYSEC-2025-166
Mar 25, 2025
8.8
/ 10
High
Network
Low
None
Required
Unchanged
High
High
High
A vulnerability was found in Open Asset Import Library Assimp 5.4.3. It has been rated as critical. Affected by this issue is the function Assimp::AC3DImporter::ConvertObjectSection of the file code/AssetLib/AC/ACLoader.cpp of the component AC3D File Handler. The manipulation of the argument src.entries leads to out-of-bounds read. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. Affected versions
0.1
3.3
4.1.1
4.1.2
4.1.3
4.1.4
5.2.5
References Updated May 21, 2026 · Source: OSV.dev
CVE-2025-2754
PYSEC-2025-165
Mar 25, 2025
8.8
/ 10
High
Network
Low
None
Required
Unchanged
High
High
High
A vulnerability was found in Open Asset Import Library Assimp 5.4.3. It has been declared as critical. Affected by this vulnerability is the function Assimp::AC3DImporter::ConvertObjectSection of the file code/AssetLib/AC/ACLoader.cpp of the component AC3D File Handler. The manipulation of the argument it leads to heap-based buffer overflow. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. Affected versions
0.1
3.3
4.1.1
4.1.2
4.1.3
4.1.4
5.2.5
References Updated May 21, 2026 · Source: OSV.dev
CVE-2025-2753
PYSEC-2025-164
Mar 25, 2025
8.8
/ 10
High
Network
Low
None
Required
Unchanged
High
High
High
A vulnerability was found in Open Asset Import Library Assimp 5.4.3. It has been classified as critical. Affected is the function SceneCombiner::MergeScenes of the file code/AssetLib/LWS/LWSLoader.cpp of the component LWS File Handler. The manipulation leads to out-of-bounds read. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. Affected versions
0.1
3.3
4.1.1
4.1.2
4.1.3
4.1.4
5.2.5
References Updated May 21, 2026 · Source: OSV.dev
CVE-2025-2752
PYSEC-2025-163
Mar 25, 2025
8.8
/ 10
High
Network
Low
None
Required
Unchanged
High
High
High
A vulnerability was found in Open Asset Import Library Assimp 5.4.3 and classified as problematic. This issue affects the function fast_atoreal_move in the library include/assimp/fast_atof.h of the component CSM File Handler. The manipulation leads to out-of-bounds read. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. Affected versions
0.1
3.3
4.1.1
4.1.2
4.1.3
4.1.4
5.2.5
References Updated May 21, 2026 · Source: OSV.dev
CVE-2025-2751
PYSEC-2025-162
Mar 25, 2025
8.8
/ 10
High
Network
Low
None
Required
Unchanged
High
High
High
A vulnerability has been found in Open Asset Import Library Assimp 5.4.3 and classified as problematic. This vulnerability affects the function Assimp::CSMImporter::InternReadFile of the file code/AssetLib/CSM/CSMLoader.cpp of the component CSM File Handler. The manipulation of the argument na leads to out-of-bounds read. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. Affected versions
0.1
3.3
4.1.1
4.1.2
4.1.3
4.1.4
5.2.5
References Updated May 21, 2026 · Source: OSV.dev
CVE-2025-2750
PYSEC-2025-161
Mar 25, 2025
8.8
/ 10
High
Network
Low
None
Required
Unchanged
High
High
High
A vulnerability, which was classified as critical, was found in Open Asset Import Library Assimp 5.4.3. This affects the function Assimp::CSMImporter::InternReadFile of the file code/AssetLib/CSM/CSMLoader.cpp of the component CSM File Handler. The manipulation leads to out-of-bounds write. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. Affected versions
0.1
3.3
4.1.1
4.1.2
4.1.3
4.1.4
5.2.5
References Updated May 21, 2026 · Source: OSV.dev
CVE-2025-2592
PYSEC-2025-260
Mar 21, 2025
8.8
/ 10
High
Network
Low
None
Required
Unchanged
High
High
High
A vulnerability, which was classified as critical, has been found in Open Asset Import Library Assimp 5.4.3. This issue affects the function CSMImporter::InternReadFile of the file code/AssetLib/CSM/CSMLoader.cpp. The manipulation leads to heap-based buffer overflow. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The patch is named 2690e354da0c681db000cfd892a55226788f2743. It is recommended to apply a patch to fix this issue. Affected versions
0.1
3.3
4.1.1
4.1.2
4.1.3
4.1.4
5.2.5
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-2591
PYSEC-2025-160
Mar 21, 2025
5.5
/ 10
Medium
Local
Low
None
Required
Unchanged
None
None
High
A vulnerability classified as problematic was found in Open Asset Import Library Assimp 5.4.3. This vulnerability affects the function MDLImporter::InternReadFile_Quake1 of the file code/AssetLib/MDL/MDLLoader.cpp. The manipulation of the argument skinwidth/skinheight leads to divide by zero. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The patch is identified as ab66a1674fcfac87aaba4c8b900b315ebc3e7dbd. It is recommended to apply a patch to fix this issue. Affected versions
0.1
3.3
4.1.1
4.1.2
4.1.3
4.1.4
5.2.5
References Updated May 21, 2026 · Source: OSV.dev
CVE-2025-2152
PYSEC-2025-159
Mar 10, 2025
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
A vulnerability, which was classified as critical, has been found in Open Asset Import Library Assimp 5.4.3. This issue affects the function Assimp::BaseImporter::ConvertToUTF8 of the file BaseImporter.cpp of the component File Handler. The manipulation leads to heap-based buffer overflow. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. Affected versions
0.1
3.3
4.1.1
4.1.2
4.1.3
4.1.4
5.2.5
References Updated May 21, 2026 · Source: OSV.dev
CVE-2025-2151
PYSEC-2025-158
Mar 10, 2025
8.8
/ 10
High
Network
Low
None
Required
Unchanged
High
High
High
A vulnerability classified as critical was found in Open Asset Import Library Assimp 5.4.3. This vulnerability affects the function Assimp::GetNextLine in the library ParsingUtils.h of the component File Handler. The manipulation leads to stack-based buffer overflow. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. Affected versions
0.1
3.3
4.1.1
4.1.2
4.1.3
4.1.4
5.2.5
References Updated May 21, 2026 · Source: OSV.dev
CVE-2024-53425
PYSEC-2024-295
Nov 21, 2024
6.2
/ 10
Medium
Local
Low
None
None
Unchanged
None
None
High
A heap-buffer-overflow vulnerability was discovered in the SkipSpacesAndLineEnd function in Assimp v5.4.3. This issue occurs when processing certain malformed MD5 model files, leading to an out-of-bounds read and potential application crash. Affected versions
0.1
3.3
4.1.1
4.1.2
4.1.3
4.1.4
5.2.5
References Updated May 21, 2026 · Source: OSV.dev
CVE-2024-48426
PYSEC-2024-294
Oct 24, 2024
6.2
/ 10
Medium
Local
Low
None
None
Unchanged
None
None
High
A segmentation fault (SEGV) was detected in the SortByPTypeProcess::Execute function in the Assimp library during fuzz testing with AddressSanitizer. The crash occurred due to a read access to an invalid memory address (0x1000c9714971). Affected versions
0.1
3.3
4.1.1
4.1.2
4.1.3
4.1.4
5.2.5
References Updated May 21, 2026 · Source: OSV.dev
CVE-2024-48425
PYSEC-2024-293
Oct 24, 2024
5.5
/ 10
Medium
Local
Low
Low
None
Unchanged
None
None
High
A segmentation fault (SEGV) was detected in the Assimp::SplitLargeMeshesProcess_Triangle::UpdateNode function within the Assimp library during fuzz testing using AddressSanitizer. The crash occurs due to a read access violation at address 0x000000000460, which points to the zero page, indicating a null or invalid pointer dereference. Affected versions
0.1
3.3
4.1.1
4.1.2
4.1.3
4.1.4
5.2.5
References Updated May 21, 2026 · Source: OSV.dev
CVE-2024-48424
PYSEC-2024-292
Oct 24, 2024
5.5
/ 10
Medium
Local
Low
Low
None
Unchanged
None
None
High
A heap-buffer-overflow vulnerability has been identified in the OpenDDLParser::parseStructure function within the Assimp library, specifically during the processing of OpenGEX files. Affected versions
0.1
3.3
4.1.1
4.1.2
4.1.3
4.1.4
5.2.5
References Updated May 21, 2026 · Source: OSV.dev
CVE-2024-48423
PYSEC-2024-120
Oct 24, 2024
7.8
/ 10
High
Local
Low
Low
None
Unchanged
High
High
High
An issue in assimp v.5.4.3 allows a local attacker to execute arbitrary code via the CallbackToLogRedirector function within the Assimp library. Affected versions
0.1
3.3
4.1.1
4.1.2
4.1.3
4.1.4
5.2.5
References Updated Nov 05, 2024 · Source: OSV.dev
CVE-2024-46632
PYSEC-2024-291
Sep 26, 2024
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
None
Low
Assimp v5.4.3 is vulnerable to Buffer Overflow via the MD5Importer::LoadMD5MeshFile function. Affected versions
0.1
3.3
4.1.1
4.1.2
4.1.3
4.1.4
5.2.5
References Updated May 21, 2026 · Source: OSV.dev | ||
0.1
initial
33 CVEs
CVE-2025-11277
PYSEC-2025-157
Oct 05, 2025
7.8
/ 10
High
Local
Low
Low
None
Unchanged
High
High
High
A weakness has been identified in Open Asset Import Library Assimp 6.0.2. This affects the function Q3DImporter::InternReadFile of the file assimp/code/AssetLib/Q3D/Q3DLoader.cpp. Executing a manipulation can lead to heap-based buffer overflow. The attack needs to be launched locally. The exploit has been made available to the public and could be used for attacks. Affected versions
0.1
3.3
4.1.1
4.1.2
4.1.3
4.1.4
5.2.5
References Updated May 21, 2026 · Source: OSV.dev
CVE-2025-11275
PYSEC-2025-156
Oct 05, 2025
7.8
/ 10
High
Local
Low
Low
None
Unchanged
High
High
High
A vulnerability was identified in Open Asset Import Library Assimp 6.0.2. Affected by this vulnerability is the function ODDLParser::getNextSeparator in the library assimp/contrib/openddlparser/include/openddlparser/OpenDDLParserUtils.h. Such manipulation leads to heap-based buffer overflow. The attack must be carried out locally. The exploit is publicly available and might be used. Affected versions
0.1
3.3
4.1.1
4.1.2
4.1.3
4.1.4
5.2.5
References Updated May 21, 2026 · Source: OSV.dev
CVE-2025-11274
PYSEC-2025-155
Oct 05, 2025
5.5
/ 10
Medium
Local
Low
Low
None
Unchanged
None
None
High
A vulnerability was determined in Open Asset Import Library Assimp 6.0.2. Affected is the function Q3DImporter::InternReadFile of the file assimp/code/AssetLib/Q3D/Q3DLoader.cpp. This manipulation causes allocation of resources. The attack is restricted to local execution. The exploit has been publicly disclosed and may be utilized. Affected versions
0.1
3.3
4.1.1
4.1.2
4.1.3
4.1.4
5.2.5
References Updated May 21, 2026 · Source: OSV.dev
CVE-2025-5169
PYSEC-2025-176
May 26, 2025
5.5
/ 10
Medium
Local
Low
Low
None
Unchanged
None
None
High
A vulnerability classified as problematic has been found in Open Asset Import Library Assimp 5.4.3. This affects the function MDLImporter::InternReadFile_3DGS_MDL345 of the file assimp/code/AssetLib/MDL/MDLLoader.cpp. The manipulation leads to out-of-bounds read. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used. The project decided to collect all Fuzzer bugs in a main-issue to address them in the future. Affected versions
0.1
3.3
4.1.1
4.1.2
4.1.3
4.1.4
5.2.5
References Updated May 21, 2026 · Source: OSV.dev
CVE-2025-5168
PYSEC-2025-175
May 26, 2025
5.5
/ 10
Medium
Local
Low
Low
None
Unchanged
None
None
High
A vulnerability was found in Open Asset Import Library Assimp 5.4.3. It has been rated as problematic. Affected by this issue is the function MDLImporter::ImportUVCoordinate_3DGS_MDL345 of the file assimp/code/AssetLib/MDL/MDLLoader.cpp. The manipulation of the argument iIndex leads to out-of-bounds read. An attack has to be approached locally. The exploit has been disclosed to the public and may be used. The project decided to collect all Fuzzer bugs in a main-issue to address them in the future. Affected versions
0.1
3.3
4.1.1
4.1.2
4.1.3
4.1.4
5.2.5
References Updated May 21, 2026 · Source: OSV.dev
CVE-2025-5167
PYSEC-2025-174
May 26, 2025
5.5
/ 10
Medium
Local
Low
Low
None
Unchanged
None
None
High
A vulnerability was found in Open Asset Import Library Assimp 5.4.3. It has been declared as problematic. Affected by this vulnerability is the function LWOImporter::GetS0 in the library assimp/code/AssetLib/LWO/LWOLoader.h. The manipulation of the argument out leads to out-of-bounds read. The attack needs to be approached locally. The exploit has been disclosed to the public and may be used. The project decided to collect all Fuzzer bugs in a main-issue to address them in the future. Affected versions
0.1
3.3
4.1.1
4.1.2
4.1.3
4.1.4
5.2.5
References Updated May 21, 2026 · Source: OSV.dev
CVE-2025-5166
PYSEC-2025-173
May 26, 2025
5.5
/ 10
Medium
Local
Low
Low
None
Unchanged
None
None
High
A vulnerability was found in Open Asset Import Library Assimp 5.4.3. It has been classified as problematic. Affected is the function MDCImporter::InternReadFile of the file assimp/code/AssetLib/MDC/MDCLoader.cpp of the component MDC File Parser. The manipulation of the argument pcVerts leads to out-of-bounds read. It is possible to launch the attack on the local host. The exploit has been disclosed to the public and may be used. The project decided to collect all Fuzzer bugs in a main-issue to address them in the future. Affected versions
0.1
3.3
4.1.1
4.1.2
4.1.3
4.1.4
5.2.5
References Updated May 21, 2026 · Source: OSV.dev
CVE-2025-5165
PYSEC-2025-172
May 26, 2025
5.5
/ 10
Medium
Local
Low
Low
None
Unchanged
None
None
High
A vulnerability was found in Open Asset Import Library Assimp 5.4.3 and classified as problematic. This issue affects the function MDCImporter::ValidateSurfaceHeader of the file assimp/code/AssetLib/MDC/MDCLoader.cpp. The manipulation of the argument pcSurface2 leads to out-of-bounds read. Attacking locally is a requirement. The exploit has been disclosed to the public and may be used. The project decided to collect all Fuzzer bugs in a main-issue to address them in the future. Affected versions
0.1
3.3
4.1.1
4.1.2
4.1.3
4.1.4
5.2.5
References Updated May 21, 2026 · Source: OSV.dev
CVE-2025-3549
PYSEC-2025-171
Apr 14, 2025
3.3
/ 10
Low
Local
Low
Low
None
Unchanged
None
None
Low
A vulnerability, which was classified as critical, was found in Open Asset Import Library Assimp 5.4.3. Affected is the function Assimp::MD3Importer::ValidateSurfaceHeaderOffsets of the file code/AssetLib/MD3/MD3Loader.cpp of the component File Handler. The manipulation leads to heap-based buffer overflow. The attack needs to be approached locally. The exploit has been disclosed to the public and may be used. Affected versions
0.1
3.3
4.1.1
4.1.2
4.1.3
4.1.4
5.2.5
References Updated May 21, 2026 · Source: OSV.dev
CVE-2025-3196
PYSEC-2025-170
Apr 04, 2025
5.5
/ 10
Medium
Local
Low
Low
None
Unchanged
None
None
High
A vulnerability, which was classified as critical, was found in Open Asset Import Library Assimp 5.4.3. Affected is the function Assimp::MD2Importer::InternReadFile in the library code/AssetLib/MD2/MD2Loader.cpp of the component Malformed File Handler. The manipulation of the argument Name leads to stack-based buffer overflow. The attack needs to be approached locally. The exploit has been disclosed to the public and may be used. It is recommended to upgrade the affected component. Affected versions
0.1
3.3
4.1.1
4.1.2
4.1.3
4.1.4
5.2.5
References Updated May 21, 2026 · Source: OSV.dev
CVE-2025-3160
PYSEC-2025-264
Apr 03, 2025
3.3
/ 10
Low
Local
Low
None
Required
Unchanged
Low
None
None
A vulnerability has been found in Open Asset Import Library Assimp 5.4.3 and classified as problematic. This vulnerability affects the function Assimp::SceneCombiner::AddNodeHashes of the file code/Common/SceneCombiner.cpp of the component File Handler. The manipulation leads to out-of-bounds read. An attack has to be approached locally. The exploit has been disclosed to the public and may be used. The patch is identified as a0993658f40d8e13ff5823990c30b43c82a5daf0. It is recommended to apply a patch to fix this issue. Affected versions
0.1
3.3
4.1.1
4.1.2
4.1.3
4.1.4
5.2.5
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-3159
PYSEC-2025-263
Apr 03, 2025
7.8
/ 10
High
Local
Low
None
Required
Unchanged
High
High
High
A vulnerability, which was classified as critical, was found in Open Asset Import Library Assimp 5.4.3. This affects the function Assimp::ASE::Parser::ParseLV4MeshBonesVertices of the file code/AssetLib/ASE/ASEParser.cpp of the component ASE File Handler. The manipulation leads to heap-based buffer overflow. The attack needs to be approached locally. The exploit has been disclosed to the public and may be used. The identifier of the patch is e8a6286542924e628e02749c4f5ac4f91fdae71b. It is recommended to apply a patch to fix this issue. Affected versions
0.1
3.3
4.1.1
4.1.2
4.1.3
4.1.4
5.2.5
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-3158
PYSEC-2025-169
Apr 03, 2025
7.8
/ 10
High
Local
Low
None
Required
Unchanged
High
High
High
A vulnerability, which was classified as critical, has been found in Open Asset Import Library Assimp 5.4.3. Affected by this issue is the function Assimp::LWO::AnimResolver::UpdateAnimRangeSetup of the file code/AssetLib/LWO/LWOAnimation.cpp of the component LWO File Handler. The manipulation leads to heap-based buffer overflow. It is possible to launch the attack on the local host. The exploit has been disclosed to the public and may be used. Affected versions
0.1
3.3
4.1.1
4.1.2
4.1.3
4.1.4
5.2.5
References Updated May 21, 2026 · Source: OSV.dev
CVE-2025-3016
PYSEC-2025-262
Mar 31, 2025
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
None
High
A vulnerability classified as problematic was found in Open Asset Import Library Assimp 5.4.3. This vulnerability affects the function Assimp::MDLImporter::ParseTextureColorData of the file code/AssetLib/MDL/MDLMaterialLoader.cpp of the component MDL File Handler. The manipulation of the argument mWidth/mHeight leads to resource consumption. The attack can be initiated remotely. Upgrading to version 6.0 is able to address this issue. The name of the patch is 5d2a7482312db2e866439a8c05a07ce1e718bed1. It is recommended to apply a patch to fix this issue. Affected versions
0.1
3.3
4.1.1
4.1.2
4.1.3
4.1.4
5.2.5
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-3015
PYSEC-2025-261
Mar 31, 2025
8.8
/ 10
High
Network
Low
None
Required
Unchanged
High
High
High
A vulnerability classified as critical has been found in Open Asset Import Library Assimp 5.4.3. This affects the function Assimp::ASEImporter::BuildUniqueRepresentation of the file code/AssetLib/ASE/ASELoader.cpp of the component ASE File Handler. The manipulation of the argument mIndices leads to out-of-bounds read. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 6.0 is able to address this issue. The patch is named 7c705fde418d68cca4e8eff56be01b2617b0d6fe. It is recommended to apply a patch to fix this issue. Affected versions
0.1
3.3
4.1.1
4.1.2
4.1.3
4.1.4
5.2.5
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-2757
PYSEC-2025-168
Mar 25, 2025
8.8
/ 10
High
Network
Low
None
Required
Unchanged
High
High
High
A vulnerability classified as critical was found in Open Asset Import Library Assimp 5.4.3. This vulnerability affects the function AI_MD5_PARSE_STRING_IN_QUOTATION of the file code/AssetLib/MD5/MD5Parser.cpp of the component MD5 File Handler. The manipulation of the argument data leads to heap-based buffer overflow. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. Affected versions
0.1
3.3
4.1.1
4.1.2
4.1.3
4.1.4
5.2.5
References Updated May 21, 2026 · Source: OSV.dev
CVE-2025-2756
PYSEC-2025-167
Mar 25, 2025
8.8
/ 10
High
Network
Low
None
Required
Unchanged
High
High
High
A vulnerability classified as critical has been found in Open Asset Import Library Assimp 5.4.3. This affects the function Assimp::AC3DImporter::ConvertObjectSection of the file code/AssetLib/AC/ACLoader.cpp of the component AC3D File Handler. The manipulation of the argument tmp leads to heap-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. Affected versions
0.1
3.3
4.1.1
4.1.2
4.1.3
4.1.4
5.2.5
References Updated May 21, 2026 · Source: OSV.dev
CVE-2025-2755
PYSEC-2025-166
Mar 25, 2025
8.8
/ 10
High
Network
Low
None
Required
Unchanged
High
High
High
A vulnerability was found in Open Asset Import Library Assimp 5.4.3. It has been rated as critical. Affected by this issue is the function Assimp::AC3DImporter::ConvertObjectSection of the file code/AssetLib/AC/ACLoader.cpp of the component AC3D File Handler. The manipulation of the argument src.entries leads to out-of-bounds read. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. Affected versions
0.1
3.3
4.1.1
4.1.2
4.1.3
4.1.4
5.2.5
References Updated May 21, 2026 · Source: OSV.dev
CVE-2025-2754
PYSEC-2025-165
Mar 25, 2025
8.8
/ 10
High
Network
Low
None
Required
Unchanged
High
High
High
A vulnerability was found in Open Asset Import Library Assimp 5.4.3. It has been declared as critical. Affected by this vulnerability is the function Assimp::AC3DImporter::ConvertObjectSection of the file code/AssetLib/AC/ACLoader.cpp of the component AC3D File Handler. The manipulation of the argument it leads to heap-based buffer overflow. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. Affected versions
0.1
3.3
4.1.1
4.1.2
4.1.3
4.1.4
5.2.5
References Updated May 21, 2026 · Source: OSV.dev
CVE-2025-2753
PYSEC-2025-164
Mar 25, 2025
8.8
/ 10
High
Network
Low
None
Required
Unchanged
High
High
High
A vulnerability was found in Open Asset Import Library Assimp 5.4.3. It has been classified as critical. Affected is the function SceneCombiner::MergeScenes of the file code/AssetLib/LWS/LWSLoader.cpp of the component LWS File Handler. The manipulation leads to out-of-bounds read. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. Affected versions
0.1
3.3
4.1.1
4.1.2
4.1.3
4.1.4
5.2.5
References Updated May 21, 2026 · Source: OSV.dev
CVE-2025-2752
PYSEC-2025-163
Mar 25, 2025
8.8
/ 10
High
Network
Low
None
Required
Unchanged
High
High
High
A vulnerability was found in Open Asset Import Library Assimp 5.4.3 and classified as problematic. This issue affects the function fast_atoreal_move in the library include/assimp/fast_atof.h of the component CSM File Handler. The manipulation leads to out-of-bounds read. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. Affected versions
0.1
3.3
4.1.1
4.1.2
4.1.3
4.1.4
5.2.5
References Updated May 21, 2026 · Source: OSV.dev
CVE-2025-2751
PYSEC-2025-162
Mar 25, 2025
8.8
/ 10
High
Network
Low
None
Required
Unchanged
High
High
High
A vulnerability has been found in Open Asset Import Library Assimp 5.4.3 and classified as problematic. This vulnerability affects the function Assimp::CSMImporter::InternReadFile of the file code/AssetLib/CSM/CSMLoader.cpp of the component CSM File Handler. The manipulation of the argument na leads to out-of-bounds read. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. Affected versions
0.1
3.3
4.1.1
4.1.2
4.1.3
4.1.4
5.2.5
References Updated May 21, 2026 · Source: OSV.dev
CVE-2025-2750
PYSEC-2025-161
Mar 25, 2025
8.8
/ 10
High
Network
Low
None
Required
Unchanged
High
High
High
A vulnerability, which was classified as critical, was found in Open Asset Import Library Assimp 5.4.3. This affects the function Assimp::CSMImporter::InternReadFile of the file code/AssetLib/CSM/CSMLoader.cpp of the component CSM File Handler. The manipulation leads to out-of-bounds write. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. Affected versions
0.1
3.3
4.1.1
4.1.2
4.1.3
4.1.4
5.2.5
References Updated May 21, 2026 · Source: OSV.dev
CVE-2025-2592
PYSEC-2025-260
Mar 21, 2025
8.8
/ 10
High
Network
Low
None
Required
Unchanged
High
High
High
A vulnerability, which was classified as critical, has been found in Open Asset Import Library Assimp 5.4.3. This issue affects the function CSMImporter::InternReadFile of the file code/AssetLib/CSM/CSMLoader.cpp. The manipulation leads to heap-based buffer overflow. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The patch is named 2690e354da0c681db000cfd892a55226788f2743. It is recommended to apply a patch to fix this issue. Affected versions
0.1
3.3
4.1.1
4.1.2
4.1.3
4.1.4
5.2.5
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-2591
PYSEC-2025-160
Mar 21, 2025
5.5
/ 10
Medium
Local
Low
None
Required
Unchanged
None
None
High
A vulnerability classified as problematic was found in Open Asset Import Library Assimp 5.4.3. This vulnerability affects the function MDLImporter::InternReadFile_Quake1 of the file code/AssetLib/MDL/MDLLoader.cpp. The manipulation of the argument skinwidth/skinheight leads to divide by zero. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The patch is identified as ab66a1674fcfac87aaba4c8b900b315ebc3e7dbd. It is recommended to apply a patch to fix this issue. Affected versions
0.1
3.3
4.1.1
4.1.2
4.1.3
4.1.4
5.2.5
References Updated May 21, 2026 · Source: OSV.dev
CVE-2025-2152
PYSEC-2025-159
Mar 10, 2025
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
A vulnerability, which was classified as critical, has been found in Open Asset Import Library Assimp 5.4.3. This issue affects the function Assimp::BaseImporter::ConvertToUTF8 of the file BaseImporter.cpp of the component File Handler. The manipulation leads to heap-based buffer overflow. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. Affected versions
0.1
3.3
4.1.1
4.1.2
4.1.3
4.1.4
5.2.5
References Updated May 21, 2026 · Source: OSV.dev
CVE-2025-2151
PYSEC-2025-158
Mar 10, 2025
8.8
/ 10
High
Network
Low
None
Required
Unchanged
High
High
High
A vulnerability classified as critical was found in Open Asset Import Library Assimp 5.4.3. This vulnerability affects the function Assimp::GetNextLine in the library ParsingUtils.h of the component File Handler. The manipulation leads to stack-based buffer overflow. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. Affected versions
0.1
3.3
4.1.1
4.1.2
4.1.3
4.1.4
5.2.5
References Updated May 21, 2026 · Source: OSV.dev
CVE-2024-53425
PYSEC-2024-295
Nov 21, 2024
6.2
/ 10
Medium
Local
Low
None
None
Unchanged
None
None
High
A heap-buffer-overflow vulnerability was discovered in the SkipSpacesAndLineEnd function in Assimp v5.4.3. This issue occurs when processing certain malformed MD5 model files, leading to an out-of-bounds read and potential application crash. Affected versions
0.1
3.3
4.1.1
4.1.2
4.1.3
4.1.4
5.2.5
References Updated May 21, 2026 · Source: OSV.dev
CVE-2024-48426
PYSEC-2024-294
Oct 24, 2024
6.2
/ 10
Medium
Local
Low
None
None
Unchanged
None
None
High
A segmentation fault (SEGV) was detected in the SortByPTypeProcess::Execute function in the Assimp library during fuzz testing with AddressSanitizer. The crash occurred due to a read access to an invalid memory address (0x1000c9714971). Affected versions
0.1
3.3
4.1.1
4.1.2
4.1.3
4.1.4
5.2.5
References Updated May 21, 2026 · Source: OSV.dev
CVE-2024-48425
PYSEC-2024-293
Oct 24, 2024
5.5
/ 10
Medium
Local
Low
Low
None
Unchanged
None
None
High
A segmentation fault (SEGV) was detected in the Assimp::SplitLargeMeshesProcess_Triangle::UpdateNode function within the Assimp library during fuzz testing using AddressSanitizer. The crash occurs due to a read access violation at address 0x000000000460, which points to the zero page, indicating a null or invalid pointer dereference. Affected versions
0.1
3.3
4.1.1
4.1.2
4.1.3
4.1.4
5.2.5
References Updated May 21, 2026 · Source: OSV.dev
CVE-2024-48424
PYSEC-2024-292
Oct 24, 2024
5.5
/ 10
Medium
Local
Low
Low
None
Unchanged
None
None
High
A heap-buffer-overflow vulnerability has been identified in the OpenDDLParser::parseStructure function within the Assimp library, specifically during the processing of OpenGEX files. Affected versions
0.1
3.3
4.1.1
4.1.2
4.1.3
4.1.4
5.2.5
References Updated May 21, 2026 · Source: OSV.dev
CVE-2024-48423
PYSEC-2024-120
Oct 24, 2024
7.8
/ 10
High
Local
Low
Low
None
Unchanged
High
High
High
An issue in assimp v.5.4.3 allows a local attacker to execute arbitrary code via the CallbackToLogRedirector function within the Assimp library. Affected versions
0.1
3.3
4.1.1
4.1.2
4.1.3
4.1.4
5.2.5
References Updated Nov 05, 2024 · Source: OSV.dev
CVE-2024-46632
PYSEC-2024-291
Sep 26, 2024
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
None
Low
Assimp v5.4.3 is vulnerable to Buffer Overflow via the MD5Importer::LoadMD5MeshFile function. Affected versions
0.1
3.3
4.1.1
4.1.2
4.1.3
4.1.4
5.2.5
References Updated May 21, 2026 · Source: OSV.dev |