Buffer Overflow vulnerability exists in Assimp versions up to 6.0.2 in the FBX Importer. The vulnerability occurs in aiMaterial::AddBinaryProperty, where a property key string from a crafted FBX file is copied into a fixed-size heap buffer using strcpy() without runtime length validation
History

Tue, 05 May 2026 02:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-122
CWE-20

Tue, 05 May 2026 00:15:00 +0000

Type Values Removed Values Added
Title Heap Buffer Overflow in Assimp FBX Importer aiMaterial::AddBinaryProperty Assimp: Assimp: Buffer overflow in FBX Importer allows arbitrary code execution via crafted file.
Weaknesses CWE-120
References
Metrics threat_severity

None

cvssV3_1

{'score': 5.6, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:L'}

threat_severity

Moderate


Mon, 04 May 2026 16:45:00 +0000

Type Values Removed Values Added
Title Heap Buffer Overflow in Assimp FBX Importer aiMaterial::AddBinaryProperty
Weaknesses CWE-122
CWE-20

Mon, 04 May 2026 15:30:00 +0000

Type Values Removed Values Added
First Time appeared Assimp
Assimp assimp
Vendors & Products Assimp
Assimp assimp

Mon, 04 May 2026 14:15:00 +0000

Type Values Removed Values Added
Description Buffer Overflow vulnerability exists in Assimp versions up to 6.0.2 in the FBX Importer. The vulnerability occurs in aiMaterial::AddBinaryProperty, where a property key string from a crafted FBX file is copied into a fixed-size heap buffer using strcpy() without runtime length validation
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-05-04T14:06:39.952Z

Reserved: 2026-01-09T00:00:00.000Z

Link: CVE-2025-70067

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-05-04T14:16:29.350

Modified: 2026-05-04T14:16:29.350

Link: CVE-2025-70067

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-05-04T00:00:00Z

Links: CVE-2025-70067 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-05-05T03:30:14Z