Impact
The vulnerability resides in the function Assimp::MDLImporter::ReadFaces_3DGS_MDL7 within the LWOLoader.h component of the Assimp library. A malformed 3DGS MDL7 model can trigger a heap-based buffer overflow. The overflow may allow an attacker to execute arbitrary code in the context of a process that loads such a model, thereby threatening confidentiality, integrity, and availability of the affected system.
Affected Systems
Open Asset Import Library (Assimp) is affected; the vulnerability exists in all versions that include the unpatched 3DGS MDL7 Model Parser. No specific version numbers are listed in the CNA data, so any build of Assimp using the vulnerable module is potentially impacted.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity, and the EPSS score is not available, so the precise likelihood of exploitation is unclear. The vulnerability can be triggered remotely by providing a crafted model file to any application that imports 3DGS MDL7 files via Assimp. It is not currently listed in the CISA KEV catalog, suggesting no confirmed exploit activity yet, though a proof‑of‑concept exists publicly.
OpenCVE Enrichment