affected: - ecosystem_specific: {} package: ecosystem: PyPI name: pyassimp purl: pkg:pypi/pyassimp ranges: - events: - introduced: '0' - last_affected: 6.0.2 type: ECOSYSTEM versions: - '0.1' - '3.3' - 4.1.1 - 4.1.2 - 4.1.3 - 4.1.4 - 5.2.5 aliases: - CVE-2025-11275 details: A vulnerability was identified in Open Asset Import Library Assimp 6.0.2. Affected by this vulnerability is the function ODDLParser::getNextSeparator in the library assimp/contrib/openddlparser/include/openddlparser/OpenDDLParserUtils.h. Such manipulation leads to heap-based buffer overflow. The attack must be carried out locally. The exploit is publicly available and might be used. id: PYSEC-2025-156 modified: '2026-05-21T14:54:38.711326Z' published: '2025-10-05T01:15:35.467Z' references: - type: ADVISORY url: https://vuldb.com/?ctiid.327009 - type: ADVISORY url: https://vuldb.com/?id.327009 - type: ADVISORY url: https://vuldb.com/?submit.658675 - type: REPORT url: https://github.com/assimp/assimp/issues/6357 - type: REPORT url: https://github.com/user-attachments/files/22417682/poc.zip severity: - score: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H type: CVSS_V3