PT-2025-40782 · Assimp+1 · Assimp+1

Sand

·

Published

2025-10-05

·

Updated

2025-10-08

·

CVE-2025-11274

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Open Asset Import Library Assimp version 6.0.2
Description A flaw exists within the Open Asset Import Library Assimp. The issue is related to resource allocation and occurs in the Q3DImporter::InternReadFile function located in the file assimp/code/AssetLib/Q3D/Q3DLoader.cpp. The exploitation of this issue is limited to local execution. The details of the exploit have been publicly disclosed.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Resource Exhaustion

Allocation of Resources Without Limits

Weakness Enumeration

Related Identifiers

CVE-2025-11274
PYSEC-2025-155

Affected Products

Assimp
Debian