CVE-2025-2753: Open Asset Import Library Assimp LWS File LWSLoader.cpp MergeScenes out-of-bounds
A vulnerability was found in Open Asset Import Library Assimp 5.4.3. It has been classified as critical. Affected is the function SceneCombiner::MergeScenes of the file code/AssetLib/LWS/LWSLoader.cpp of the component LWS File Handler. The manipulation leads to out-of-bounds read. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-2753?
CVE-2025-2753 has been classified as a critical vulnerability.
What does CVE-2025-2753 affect?
CVE-2025-2753 affects the Open Asset Import Library Assimp version 5.4.3, specifically the SceneCombiner::MergeScenes function in the LWS File Handler.
What type of vulnerability is CVE-2025-2753?
CVE-2025-2753 involves an out-of-bounds read vulnerability which can lead to unintended memory access.
How do I fix CVE-2025-2753?
To fix CVE-2025-2753, upgrade Open Asset Import Library Assimp to a patched version that addresses this vulnerability.
Is CVE-2025-2753 easily exploitable?
Due to its critical nature, CVE-2025-2753 may be susceptible to exploitation under certain conditions.