CVE-2020-13531: Pixar Openusd

High severity, CVSS 8.8. EPSS: 2.8% chance of exploitation in the next 30 days.

A use-after-free vulnerability exists in a way Pixar OpenUSD 20.08 processes reference paths textual USD files. A specially crafted file can trigger the reuse of a freed memory which can result in further memory corruption and arbitrary code execution. To trigger this vulnerability, the victim needs to open an attacker-provided malformed file.

Affected products

  • Pixar Openusd: version 20.08 only

Published 2020-12-03. Last modified 2026-06-17.