CVE-2025-11277: Assimp
High severity, CVSS 7.8. EPSS: 0.2% chance of exploitation in the next 30 days.
A weakness has been identified in Open Asset Import Library Assimp 6.0.2. This affects the function Q3DImporter::InternReadFile of the file assimp/code/AssetLib/Q3D/Q3DLoader.cpp. Executing a manipulation can lead to heap-based buffer overflow. The attack needs to be launched locally. The exploit has been made available to the public and could be used for attacks.
Affected products
- Assimp Assimp: version 6.0.2 only
Published 2025-10-05. Last modified 2026-10-08.