Junglewise Threat Intelligence

CVE-2026-16781: Autodesk 3ds Max uncontrolled recursion in SVG parsing

CVE-2026-16781 · Severity: medium · CVSS 5.5 · Published 2026-08-24

Technologies: Autodesk 3ds Max. Vendors: Autodesk.

Executive brief

Autodesk 3ds Max is a professional 3D modeling and animation tool used across design and entertainment industries. A specially crafted SVG file can cause the application to crash due to an uncontrolled recursion flaw, allowing an attacker to disrupt a user's work and availability when a malicious file is opened.

Technical details

The vulnerability is an uncontrolled recursion flaw in Autodesk 3ds Max's SVG file parser. When a maliciously crafted SVG file is parsed by the application, the recursive parsing logic fails to properly limit recursion depth, causing a stack overflow. An attacker can deliver a malicious SVG file to a user (via email, file sharing, or web download), and if opened in 3ds Max, triggers the crash. The vulnerability requires user interaction (opening the file). Patches or fixes should be available from Autodesk's security advisory.

Affected products

  • Autodesk 3ds Max

Timeline

  • 2026-08-24: disclosed

References

Related threats