Executive brief
Assimp is a widely used library for importing 3D models into applications and games. A vulnerability in its FBX file importer allows an attacker to crash the application or potentially execute malicious code by providing a specially crafted 3D model file. This could lead to a total compromise of the system running the software or a disruption of services that process user-uploaded 3D assets.
Technical details
A heap-based buffer overflow exists in Assimp up to version 6.0.2 within the `aiMaterial::AddBinaryProperty` function in `code/Material/MaterialSystem.cpp`. The vulnerability stems from the use of `strcpy()` to copy a property key string from an FBX file into a fixed-size `aiString` buffer without runtime length validation. While a length check exists via `ai_assert`, this check is compiled out in Release and RelWithDebInfo builds (where `NDEBUG` is defined), leaving the `strcpy` operation unbounded. An attacker who can convince a user or service to import a malicious FBX file can cause a heap overflow, potentially leading to remote code execution or a denial-of-service (crash). A patch has been identified in the project's repository.
Affected products
- Assimp project Assimp (Open Asset Import Library) Up to 6.0.2
Timeline
- 2026-05-04: advisory: Initial disclosure and NVD publication
- 2026-05-18: patched: Fix commit identified in GitHub repository