CVE-2025-11275EPSS p14.6%
CVE-2025-11275CVE-2025-11275
assimp / assimp
Description
A vulnerability was identified in Open Asset Import Library Assimp 6.0.2. Affected by this vulnerability is the function ODDLParser::getNextSeparator in the library assimp/contrib/openddlparser/include/openddlparser/OpenDDLParserUtils.h. Such manipulation leads to heap-based buffer overflow. The attack must be carried out locally. The exploit is publicly available and might be used.
Scoring
| CVSS | 5.3 () |
| Vector | CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L |
| EPSS | 0.25% probability of exploitation · percentile 14.6% · 2026-10-10T12:00:23Z |
| Last modified | 2026-10-08 |