Description
A security vulnerability has been detected in Assimp up to 6.0.4. Affected by this issue is the function HL1MDLLoader::read_sequence_infos of the file HL1MDLLoader.cpp of the component Half-Life 1 MDL Loader. The manipulation of the argument aiString leads to out-of-bounds read. The attack needs to be performed locally. The exploit has been disclosed publicly and may be used. The project tagged the reported issue as bug.
Problem types
Timeline
| 2026-05-31: | Advisory disclosed |
| 2026-05-31: | VulDB entry created |
| 2026-05-31: | VulDB entry last update |
Credits
TYGLS (VulDB User)
VulDB CNA Team
References
github.com/assimp/assimp/issues/6619
vuldb.com/vuln/367512 (VDB-367512 | Assimp Half-Life 1 MDL Loader HL1MDLLoader.cpp read_sequence_infos out-of-bounds)
vuldb.com/vuln/367512/cti (VDB-367512 | CTI Indicators (IOB, IOC, IOA))
vuldb.com/cve/CVE-2026-10233 (CVE-2026-10233 | CVE Analysis and Report)
vuldb.com/submit/821196 (Submit #821196 | Assimp commit 17c12da Buffer Overflow)
github.com/assimp/assimp/issues/6619
github.com/user-attachments/files/27228962/poc.zip
github.com/assimp/assimp/