CVE-2026-10232

Source
https://cve.org/CVERecord?id=CVE-2026-10232
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-10232.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-10232
Downstream
Related
Published
2026-06-01T06:30:10.110Z
Modified
2026-07-15T01:48:50.288094502Z
Severity
  • 1.9 (Low) CVSS_V4 - CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P CVSS Calculator
Summary
Assimp ASE File scene.cpp ~aiNode use after free
Details

A weakness has been identified in Assimp up to 6.0.4. Affected by this vulnerability is the function aiNode::~aiNode of the file scene.cpp of the component ASE File Parser. Executing a manipulation can lead to use after free. The attack needs to be launched locally. The exploit has been made available to the public and could be used for attacks. The project tagged the reported issue as bug.

Database specific
{
    "cwe_ids": [
        "CWE-119",
        "CWE-416"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/10xxx/CVE-2026-10232.json",
    "cna_assigner": "VulDB"
}
References

Affected packages

Git / github.com/assimp/assimp

Affected ranges

Type
GIT
Repo
https://github.com/assimp/assimp
Events
Database specific
{
    "extracted_events": [
        {
            "introduced": "6.0.0"
        },
        {
            "last_affected": "6.0.0"
        },
        {
            "introduced": "6.0.1"
        },
        {
            "last_affected": "6.0.1"
        },
        {
            "introduced": "6.0.2"
        },
        {
            "last_affected": "6.0.2"
        },
        {
            "introduced": "6.0.3"
        },
        {
            "last_affected": "6.0.3"
        },
        {
            "introduced": "6.0.4"
        },
        {
            "last_affected": "6.0.4"
        }
    ],
    "source": "AFFECTED_FIELD"
}

Affected versions

6.*
6.0.0
6.0.1
6.0.2
6.0.3
6.0.4
v6.*
v6.0.0
v6.0.1
v6.0.2
v6.0.3
v6.0.4

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-10232.json"