CVE-2026-19970 | Open Asset Import Library Assimp 17c12da Node Parser MDLLoader.cpp AddBonesToNodeGraph_3DGS_MDL7 bones_num heap-based overflow (Issue 6632)

SecurityVulns

A vulnerability classified as critical was found in Open Asset Import Library Assimp 17c12da. This affects the function Assimp::MDLImporter::AddBonesToNodeGraph_3DGS_MDL7 of the file code/AssetLib/MDL/MDLLoader.cpp of the component Node Parser. The manipulation of the argument bones_num results in heap-based buffer overflow.

This vulnerability is identified as CVE-2026-19970. The attack can be executed remotely. Additionally, an exploit exists.

The project was informed of the problem early through an issue report but has not responded yet.VulDB Recent EntriesRead More