Launch Week Day 1: Announcing Security Design Review
HIGH 7.8 PyPI

CVE-2025-11277

PYSEC-2025-157 · CVE-2025-11277

Published · Modified

Description

A weakness has been identified in Open Asset Import Library Assimp 6.0.2. This affects the function Q3DImporter::InternReadFile of the file assimp/code/AssetLib/Q3D/Q3DLoader.cpp. Executing a manipulation can lead to heap-based buffer overflow. The attack needs to be launched locally. The exploit has been made available to the public and could be used for attacks.

Ready to move

Start Securing

Free, no credit card | First findings in minutes