Junglewise Threat Intelligence

CVE-2026-10201: Assimp divide by zero in FBXExporter

CVE-2026-10201 · Severity: low · CVSS 3.3 · Published 2026-06-01

Technologies: Assimp. Vendors: Assimp.

Executive brief

Assimp is a widely used library for importing and exporting 3D model files. A vulnerability in its FBX export component can cause the software to crash when processing a specially crafted 3D model. This could lead to a denial-of-service, interrupting workflows for users or automated systems that process 3D assets.

Technical details

A division-by-zero vulnerability (CWE-369) exists in Assimp up to version 6.0.4 within the FBXExporter::WriteObjects function in FBXExporter.cpp. The issue is triggered when the UV Channel Handler encounters a UV channel that exists but contains zero components. An attacker with local access can exploit this by providing a manipulated 3D model for export, leading to an application crash (denial of service). A proof-of-concept has been publicly disclosed, and the issue is tracked by the project as a bug in the FBX export logic.

Affected products

  • Assimp Assimp up to 6.0.4

Timeline

  • 2026-04-28: disclosed: Issue reported on GitHub repository
  • 2026-06-01: advisory: CVE published

References

Related threats