CVE-2026-10230

Medium severity, CVSS 5.3. EPSS: 0.1% chance of exploitation in the next 30 days.

A vulnerability was identified in Assimp up to 6.0.4. This impacts the function Assimp::MDL::HalfLife::HL1MDLLoader::read_animations of the file HL1MDLLoader.cpp of the component Half-Life 1 MDL Loader. Such manipulation leads to heap-based buffer overflow. The attack must be carried out locally. The exploit is publicly available and might be used. The project tagged the reported issue as bug.

Published 2026-06-01. Last modified 2026-07-22.