{"id":"JLSEC-2026-188","details":"Heap-based buffer overflow vulnerability in Assimp versions prior to 5.4.3 allows a local attacker to execute arbitrary code by importing a specially crafted file into the product.","modified":"2026-07-18T00:00:28.270375108Z","published":"2026-04-27T13:14:20.203Z","upstream":["CVE-2024-45679"],"database_specific":{"sources":[{"url":"https://services.nvd.nist.gov/rest/json/cves/2.0?cveId=CVE-2024-45679","html_url":"https://nvd.nist.gov/vuln/detail/CVE-2024-45679","database_specific":{"status":"Analyzed"},"id":"CVE-2024-45679","imported":"2026-07-17T21:19:13.491Z","modified":"2026-06-17T07:54:39.240Z","published":"2024-09-18T04:15:42.080Z"}],"license":"CC-BY-4.0"},"references":[{"type":"WEB","url":"https://github.com/assimp/assimp/releases/tag/v5.4.3"},{"type":"WEB","url":"https://jvn.jp/en/jp/JVN42386607/"}],"affected":[{"package":{"name":"assimp_jll","ecosystem":"Julia","purl":"pkg:julia/assimp_jll?uuid=54ae6823-98c6-5a7c-8365-5a43b909f91f"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"6.0.4+0"}]}],"database_specific":{"source":"https://github.com/JuliaLang/SecurityAdvisories.jl/tree/generated/osv/2026/JLSEC-2026-188.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}