CVE-2025-15538

MEDIUM

Assimp < 6.0.2 - Use After Free

Title source: rule
STIX 2.1

Description

A security vulnerability has been detected in Open Asset Import Library Assimp up to 6.0.2. Affected by this vulnerability is the function Assimp::LWOImporter::FindUVChannels of the file /src/assimp/code/AssetLib/LWO/LWOMaterial.cpp. Such manipulation leads to use after free. The attack needs to be performed locally. The exploit has been disclosed publicly and may be used. This and similar defects are tracked and handled via issue #6128.

References (6)

Core 6
Core References
Third Party Advisory, VDB Entry vdb-entry technical-description
https://vuldb.com/?id.341727
Permissions Required, VDB Entry signature permissions-required
https://vuldb.com/?ctiid.341727
Third Party Advisory, VDB Entry third-party-advisory
https://vuldb.com/?submit.735232
Exploit, Issue Tracking issue-tracking
https://github.com/assimp/assimp/issues/6258

Scores

CVSS v3 5.3
EPSS 0.0003
EPSS Percentile 7.3%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-119 CWE-416
Status published
Products (1)
assimp/assimp < 6.0.2
Published Jan 18, 2026
Tracked Since Feb 18, 2026