CVE-2026-10229
Medium severity, CVSS 5.3. EPSS: 0.1% chance of exploitation in the next 30 days.
A vulnerability was determined in Assimp up to 6.0.4. This affects the function HL1MDLLoader::read_meshes of the file HL1MDLLoader.cpp of the component Half-Life 1 MDL Loader. This manipulation causes heap-based buffer overflow. The attack is restricted to local execution. The exploit has been publicly disclosed and may be utilized. The project tagged the reported issue as bug.
Published 2026-06-01. Last modified 2026-07-22.