Executive brief
Assimp is a widely used library for importing and exporting 3D model files. A vulnerability in its FBX export component can cause the software to crash when processing a specially crafted 3D model. This could lead to a denial-of-service, interrupting workflows for users or automated systems that process 3D assets.
Technical details
A division-by-zero vulnerability (CWE-369) exists in Assimp up to version 6.0.4 within the FBXExporter::WriteObjects function in FBXExporter.cpp. The issue is triggered when the UV Channel Handler encounters a UV channel that exists but contains zero components. An attacker with local access can exploit this by providing a manipulated 3D model for export, leading to an application crash (denial of service). A proof-of-concept has been publicly disclosed, and the issue is tracked by the project as a bug in the FBX export logic.
Affected products
- Assimp Assimp up to 6.0.4
Timeline
- 2026-04-28: disclosed: Issue reported on GitHub repository
- 2026-06-01: advisory: CVE published