VDB
CVE-2026-10232
CVE-2026-10232
PUBLISHED
CVSS 4.8 MEDIUM
Reported by VulDB · Published June 1, 2026
A weakness has been identified in Assimp up to 6.0.4. Affected by this vulnerability is the function aiNode::~aiNode of the file scene.cpp of the component ASE File Parser. Executing a manipulation can lead to use after free. The attack needs to be launched locally. The exploit has been made available to the public and could be used for attacks. The project tagged the reported issue as bug.
Risk Scores
CVSS 4.0
4.8
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| n/a | Assimp | 6.0.0, 6.0.1, 6.0.2 |
| n/a | Assimp | 6.0.0, 6.0.1, 6.0.2 |
Timeline
- Jun 1, 2026 EPSS Score
- Jun 1, 2026 CVE Published
- Jun 2, 2026 Security Advisory
- Jun 2, 2026 CVE Updated
- Jun 5, 2026 EPSS Score
- Jun 11, 2026 Coalition ESS Score
- Aug 7, 2026 EPSS Score
References
- VDB-367511 | Assimp ASE File scene.cpp ~aiNode use after free vdb-entrytechnical-description
- VDB-367511 | CTI Indicators (IOB, IOC, IOA) signaturepermissions-required
- CVE-2026-10232 | CVE Analysis and Report third-party-advisory
- Submit #821192 | Assimp commit 17c12da Memory Corruption third-party-advisory
- issue-tracking
- exploit
- product