PT-2026-45275 · Undefined · Undefined

Tygls

·

Published

2026-06-01

·

Updated

2026-06-01

·

CVE-2026-10231

CVSS v2.0

4.3

Medium

VectorAV:L/AC:L/Au:S/C:P/I:P/A:P
A security flaw has been discovered in Assimp up to 6.0.4. Affected is the function HL1MDLLoader::extract anim value of the file HL1MDLLoader.cpp of the component Half-Life 1 MDL Loader. Performing a manipulation of the argument num.total results in heap-based buffer overflow. The attack must be initiated from a local position. The exploit has been released to the public and may be used for attacks. The project tagged the reported issue as bug.

Exploit

Fix

Heap Based Buffer Overflow

Buffer Overflow

Weakness Enumeration

Related Identifiers

CVE-2026-10231

Affected Products

Undefined