CVE-2026-10233
Gravedad CVSS v4.0:
BAJA
Tipo:
CWE-119
Restricción de operaciones inapropiada dentro de los límites del búfer de la memoria
Fecha de publicación:
01/06/2026
Última modificación:
03/06/2026
Descripción
*** Pendiente de traducción *** A security vulnerability has been detected in Assimp up to 6.0.4. Affected by this issue is the function HL1MDLLoader::read_sequence_infos of the file HL1MDLLoader.cpp of the component Half-Life 1 MDL Loader. The manipulation of the argument aiString leads to out-of-bounds read. The attack needs to be performed locally. The exploit has been disclosed publicly and may be used. The project tagged the reported issue as bug.
Impacto
Puntuación base 4.0
1.90
Gravedad 4.0
BAJA
Puntuación base 3.x
3.30
Gravedad 3.x
BAJA
Puntuación base 2.0
1.70
Gravedad 2.0
BAJA
Referencias a soluciones, herramientas e información
- https://github.com/assimp/assimp/
- https://github.com/assimp/assimp/issues/6619
- https://github.com/user-attachments/files/27228962/poc.zip
- https://vuldb.com/cve/CVE-2026-10233
- https://vuldb.com/submit/821196
- https://vuldb.com/vuln/367512
- https://vuldb.com/vuln/367512/cti
- https://github.com/assimp/assimp/issues/6619



