CVE-2026-14604 Details
Description
A vulnerability was determined in Open Asset Import Library Assimp up to 6.0.4. Affected is the function Assimp::Exporter::ExportToBlob of the file code/AssetLib/Ply/PlyLoader.cpp of the component PLY Model Handler. This manipulation causes double free. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized. The project was informed of the problem early through an issue report.
A double free vulnerability has been identified in Open Asset Import Library (Assimp) versions through 6.0.4, specifically within the PLY Model Handler. The issue arises in the function 'Assimp::Exporter::ExportToBlob' in 'PlyLoader.cpp', where conflicting memory ownership leads to double free memory corruption. This vulnerability can be exploited remotely.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jul 3, 2026CISA-ADP
Assessed Jul 6, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/assimp/assimp/issues/6620 | [email protected] | ExploitIssue TrackingTechnical DescriptionVendor |
| https://github.com/user-attachments/files/27232640/poc.zip | [email protected] | Broken LinkExploit |
| https://vuldb.com/cve/CVE-2026-14604 | [email protected] | AdvisoryPermission Required |
| https://vuldb.com/submit/844567 | [email protected] | Issue TrackingPermission Required |
| https://vuldb.com/vuln/376112 | [email protected] | Content Wall |
| https://vuldb.com/vuln/376112/cti | [email protected] | Content Wall |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-119 | Improper Restriction of Operations within the Bounds of a Memory Buffer | [email protected] |
| CWE-415 | Double Free | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Open Asset Import Library Assimp | <= 6.0.4 (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 6, 2026 | CVE Modified | CISA-ADP |
| Jul 3, 2026 | New CVE Received | [email protected] |
Volerion