CVE-2026-14610: Open Asset Import Library Assimp CSM File CSMLoader.cpp InternReadFile heap-based overflow
A flaw has been found in Open Asset Import Library Assimp up to 6.0.5. Impacted is the function Assimp::CSMImporter::InternReadFile of the file code/AssetLib/CSM/CSMLoader.cpp of the component CSM File Handler. This manipulation causes heap-based buffer overflow. The attack is restricted to local execution. The exploit has been published and may be used. Patch name: eb84eec580d3f4ba2f0fd87409b7d0744620f11e. Applying a patch is the recommended action to fix this issue.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Open Asset Import Library (Assimp) Assimp CSM File Handlerto a version that resolves this vulnerability.Fixed in 6.0.5Patch eb84eec580d3f4ba2f0fd87409b7d0744620f11e - Compensating control
Because the exploit is published and may be used (local execution), restrict access so only trusted users/processes can run the affected Assimp component (e.g., limit execution permissions/sandboxing for processes that load CSM files).
Event History
Frequently Asked Questions
What is the severity of CVE-2026-14610?
CVE-2026-14610 has a severity rating of medium with a score of 5.3.
What type of vulnerability is identified by CVE-2026-14610?
CVE-2026-14610 is classified as a heap-based buffer overflow vulnerability.
How does CVE-2026-14610 affect affected systems?
CVE-2026-14610 allows for a heap-based buffer overflow, potentially compromising the security of local systems running affected versions of Assimp.
Which versions of Assimp are affected by CVE-2026-14610?
CVE-2026-14610 affects versions of Open Asset Import Library Assimp up to 6.0.5.
How can I mitigate the risks associated with CVE-2026-14610?
To mitigate CVE-2026-14610, users should update to the latest version of the Assimp library that addresses this vulnerability.