Junglewise Threat Intelligence

CVE-2026-10231: Assimp heap overflow in HL1MDLLoader

CVE-2026-10231 · Severity: medium · CVSS 5.3 · Published 2026-06-01

Technologies: Assimp. Vendors: Assimp.

Executive brief

Assimp is a widely used library for importing various 3D model formats into applications. A security flaw in its Half-Life 1 model loader could allow an attacker with local access to trigger a memory error by providing a specially crafted file. This could lead to application crashes or potentially unauthorized access to data within the system's memory.

Technical details

A heap-based buffer overflow exists in Assimp versions up to 6.0.4 within the HL1MDLLoader::extract_anim_value function in HL1MDLLoader.cpp. The vulnerability is triggered by manipulating the 'num.total' argument, specifically when it is set to zero, leading to improper memory bounds handling during the extraction of animation values from Half-Life 1 MDL files. An attacker with local access can exploit this by providing a malformed MDL file to an application using the library. Successful exploitation could result in a denial-of-service (crash) or potentially limited information disclosure and integrity loss. A public proof-of-concept exploit has been released.

Affected products

  • Assimp Assimp up to 6.0.4

Timeline

  • 2026-06-01: advisory: Vulnerability published by VulDB and NVD

References

Related threats