Skip to content

Security: memory-safety bugs in binary FBX parser — need a private disclosure channel #119

Description

@vikram183

Hi @nem0,

I found two memory-safety defects in the binary-FBX parser that are reachable from the public ofbx::load() entry point with attacker-controlled input (crafted .fbx file). I have reproducible PoCs and suggested fixes, but I don't want to post details publicly before a fix is available.

There's no SECURITY.md or private vulnerability reporting on this repo. Could you either:

  1. Enable Private Vulnerability Reporting (repo Settings → Security → enable), which adds a "Report a vulnerability" button I can use, or
  2. Share a security contact (email) I can send the full report to?

Happy to follow coordinated disclosure and hold the PoCs until a fix lands.
Thanks!

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions