Assimp is a widely embedded open-source asset-import library that converts 3D model file formats from external sources into in-memory representations for graphics applications and game engines. Despite a very narrow product scope, the library's prominence in the 3D graphics pipeline means vulnerabilities can propagate to any application that parses untrusted model files, creating a distributed attack surface across game development, animation, CAD, and visualization software. The vendor's vulnerability profile clusters durably around memory-safety issues—out-of-bounds reads and writes, heap buffer overflows, and classic buffer-overflow conditions—that arise from parsing complex and variable-length 3D file formats without exhaustive bounds checking. The low severity tendency and negligible exploitation profile reflect the library's typical deployment context: file parsing of offline or design-time assets rather than live network-facing operations, though defenders should still track this vendor's releases when Assimp is integrated into file-upload or content-pipeline workflows. Current severity and exploitation counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Assimp over time
Signals from CVEs in this vendor scope (47 CVEs).
47 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-11277HIGH A weakness has been identified in Open Asset Import Library Assimp 6.0.2. This affects the function Q3DImporter::InternReadFile of the file assimp/code/AssetLib/Q3D/Q3DLoader.cpp. | Oct 5, 2025 | 7.8 | 27 | NO | NO |
CVE-2022-45748HIGH An issue was discovered with assimp 5.1.4, a use after free occurred in function ColladaParser::ExtractDataObjectFromChannel in file /code/AssetLib/Collada/ColladaParser.cpp. | Jan 20, 2023 | 8.8 | 27 | NO | NO |
CVE-2025-3015HIGH A vulnerability classified as critical has been found in Open Asset Import Library Assimp 5.4.3. This affects the function Assimp::ASEImporter::BuildUniqueRepresentation of the fil | Mar 31, 2025 | 8.8 | 26 | NO | NO |
CVE-2025-2152CRITICAL A vulnerability, which was classified as critical, has been found in Open Asset Import Library Assimp 5.4.3. This issue affects the function Assimp::BaseImporter::ConvertToUTF8 of | Mar 10, 2025 | 9.8 | 26 | NO | NO |
CVE-2025-15538HIGH A security vulnerability has been detected in Open Asset Import Library Assimp up to 6.0.2. Affected by this vulnerability is the function Assimp::LWOImporter::FindUVChannels of th | Jan 18, 2026 | 7.8 | 25 | NO | NO |
CVE-2025-11275HIGH A vulnerability was identified in Open Asset Import Library Assimp 6.0.2. Affected by this vulnerability is the function ODDLParser::getNextSeparator in the library assimp/contrib/ | Oct 5, 2025 | 7.8 | 25 | NO | NO |
CVE-2025-2592HIGH A vulnerability, which was classified as critical, has been found in Open Asset Import Library Assimp 5.4.3. This issue affects the function CSMImporter::InternReadFile of the file | Mar 21, 2025 | 8.8 | 25 | NO | NO |
CVE-2025-2151HIGH A vulnerability classified as critical was found in Open Asset Import Library Assimp 5.4.3. This vulnerability affects the function Assimp::GetNextLine in the library ParsingUtils. | Mar 10, 2025 | 8.8 | 25 | NO | NO |
CVE-2025-5204HIGH A vulnerability classified as problematic has been found in Open Asset Import Library Assimp 5.4.3. This affects the function MDLImporter::ParseSkinLump_3DGS_MDL7 of the file assim | May 26, 2025 | 7.8 | 24 | NO | NO |
CVE-2025-2752HIGH A vulnerability was found in Open Asset Import Library Assimp 5.4.3 and classified as problematic. This issue affects the function fast_atoreal_move in the library include/assimp/f | Mar 25, 2025 | 8.8 | 24 | NO | NO |
Signals from CVEs in this vendor scope (47 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Assimp.
Media articles that mention a CVE ID that affects a product developed by Assimp — matched by CVE ID, not by vendor name.