Executive brief
Open Asset Import Library (Assimp) is a widely-used library for importing 3D model file formats used by graphics applications, game engines, and media software. A heap buffer overflow vulnerability in the file decompression function allows an attacker to crash the application or potentially execute arbitrary code by sending a specially crafted 3D model file over the network.
Technical details
The vulnerability is a heap-based buffer overflow in the Assimp::Compression::decompressBlock function within code/Common/Compression.cpp. The flaw occurs during the parsing and decompression of model file data. An attacker can trigger the overflow by crafting a malicious 3D model file that is processed by a vulnerable application. The attack vector is network-based and requires no authentication or user interaction beyond loading the malicious file. An exploit has been publicly released. The vulnerability can lead to denial of service or code execution, depending on memory layout and exploitation technique.
Affected products
- Assimp Open Asset Import Library including commit 17c12da
Timeline
- 2026-08-17: disclosed
- other: Exploit publicly released