CVE-2026-10200: Assimp 4x4 Matrix glTFCommon.h CopyValue heap-based overflow

Published May 31, 2026
·
Updated

A vulnerability was found in Assimp up to 6.0.4. This affects the function glTFCommon::CopyValue in the library glTFCommon.h of the component 4x4 Matrix Parser. Performing a manipulation results in heap-based buffer overflow. The attack must be initiated from a local position. The exploit has been made public and could be used. The project tagged the reported issue as bug.

Affected Software

1 affected component
Assimp Assimp<=6.0.4

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Remove

    Remove Assimp from your environment.

    If Assimp is not required, uninstall or remove the library/binaries from affected hosts (versions up to 6.0.4) until a patch is released.

  2. Compensating control

    Restrict local access to systems running Assimp. Prevent untrusted local users or processes from supplying or processing glTF files (use host-based controls, sandboxing, ACLs, or similar measures) because the attack must be initiated from a local position.

  3. Operational

    Do not process untrusted glTF files with vulnerable Assimp versions (any version up to 6.0.4) until a vendor fix is available.

  4. Operational

    Monitor for exploitation attempts and signs of compromise related to glTF processing (the exploit has been made public). Investigate and isolate suspicious hosts and prioritize applying vendor fixes when they are released.

Event History

May 31, 2026
CVE Published
via MITRE·10:45 PM
Data Sourced
via MITRE·10:45 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·11:16 PM
DescriptionSeverityWeakness
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2026-10200?

The severity of CVE-2026-10200 is classified as low with a severity score of 1.9.

2

How do I fix CVE-2026-10200?

To mitigate CVE-2026-10200, update to Assimp version 6.0.5 or later, where the vulnerability has been addressed.

3

What type of vulnerability is CVE-2026-10200?

CVE-2026-10200 is a buffer overflow vulnerability specifically affecting the 4x4 Matrix Parser in Assimp.

4

What are the potential impacts of CVE-2026-10200 if exploited?

If exploited, CVE-2026-10200 could lead to a heap-based buffer overflow, potentially allowing an attacker to execute arbitrary code.

5

Which component of Assimp is affected by CVE-2026-10200?

CVE-2026-10200 affects the function glTFCommon::CopyValue in the glTFCommon.h component of Assimp.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203