affected: - ecosystem_specific: {} package: ecosystem: PyPI name: pyassimp purl: pkg:pypi/pyassimp ranges: - events: - introduced: '0' - last_affected: 5.4.3 type: ECOSYSTEM versions: - '0.1' - '3.3' - 4.1.1 - 4.1.2 - 4.1.3 - 4.1.4 - 5.2.5 aliases: - CVE-2024-46632 details: Assimp v5.4.3 is vulnerable to Buffer Overflow via the MD5Importer::LoadMD5MeshFile function. id: PYSEC-2024-291 modified: '2026-05-21T14:54:38.381490Z' published: '2024-09-26T16:15:08.783Z' references: - type: REPORT url: https://github.com/assimp/assimp/issues/5771 severity: - score: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L type: CVSS_V3