CVE-2026-10198: Assimp glTFImporter glTFImporter.cpp ImportMeshes null pointer dereference
A flaw has been found in Assimp up to 6.0.4. Affected by this vulnerability is the function Assimp::glTFImporter::ImportMeshes of the file glTFImporter.cpp of the component glTFImporter. This manipulation causes null pointer dereference. The attack is restricted to local execution. The exploit has been published and may be used. The project tagged the reported issue as bug.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2026-10198?
CVE-2026-10198 is a vulnerability in Assimp up to version 6.0.4 that allows for a null pointer dereference in the glTFImporter component.
What is the severity of CVE-2026-10198?
The severity of CVE-2026-10198 is rated low with a score of 3.3.
How do I fix CVE-2026-10198?
To fix CVE-2026-10198, update to the latest version of Assimp that addresses this vulnerability.
What systems are affected by CVE-2026-10198?
CVE-2026-10198 affects systems running Assimp software up to version 6.0.4.
Can CVE-2026-10198 be exploited remotely?
CVE-2026-10198 requires local execution for exploitation and cannot be exploited remotely.