Executive brief
Assimp, a library used to import 3D models into various applications, contains a vulnerability in its Half-Life 1 model loader. An attacker can provide a specially crafted 3D model file that, when processed, causes the application to crash or potentially execute unauthorized code. This could lead to a loss of system stability or unauthorized access to data on the local machine.
Technical details
A heap-based buffer overflow exists in Assimp up to version 6.0.4 within the HL1MDLLoader::read_meshes function in HL1MDLLoader.cpp. The vulnerability is triggered when parsing a malformed Half-Life 1 MDL file where vertex data references a bone index that exceeds the number of bones declared in the file header (e.g., referencing index 5 when only 1 bone is defined). This results in an out-of-bounds read/write on the temp_bones_ vector. An attacker with local access can exploit this by providing a malicious MDL file to an application using the library, potentially achieving arbitrary code execution or a denial-of-service. A public proof-of-concept (PoC) has been disclosed.
Affected products
- Assimp Assimp up to 6.0.4
Timeline
- 2026-06-01: disclosed: Vulnerability disclosed and CVE assigned.
- 2026-06-01: advisory: NVD and VulDB published advisories.