CVE-2025-70067
the affected product
Buffer Overflow vulnerability exists in Assimp versions up to 6.0.2 in the FBX Importer. The vulnerability occurs in aiMaterial::AddBinaryProperty, where a property key string from a crafted FBX file is copied into a fixed-size heap buffer using strcpy() without runtime length validation
- CVSS
- 9.8
- EPSS
- 0.34% 26.7% percentile
- CISA KEV
- Not listed
- Published
- 2026.05.04