CVE-2025-11274: Assimp

Medium severity, CVSS 5.5. EPSS: 0.2% chance of exploitation in the next 30 days.

A vulnerability was determined in Open Asset Import Library Assimp 6.0.2. Affected is the function Q3DImporter::InternReadFile of the file assimp/code/AssetLib/Q3D/Q3DLoader.cpp. This manipulation causes allocation of resources. The attack is restricted to local execution. The exploit has been publicly disclosed and may be utilized.

Affected products

  • Assimp Assimp: version 6.0.2 only

Published 2025-10-05. Last modified 2026-10-08.