PT-2025-31590 · Openexr+1 · Openexr+1

Ndaprela

+3

·

Published

2025-07-31

·

Updated

2025-08-20

·

CVE-2025-53009

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions MaterialX versions 1.39.2 and below
Description MaterialX is an open standard for the exchange of rich material and look-development content across applications and renderers. The MaterialX XML parsing logic can potentially crash due to stack exhaustion when parsing an MTLX file with multiple nested nodegraph implementations. An attacker could intentionally crash a target program that uses OpenEXR by sending a malicious MTLX file.
Recommendations Update to version 1.39.3 or later.

Exploit

Fix

Stack Overflow

Weakness Enumeration

Related Identifiers

CVE-2025-53009
GHSA-WX6G-FM6F-W822

Affected Products

Materialx
Openexr