CVE Database
/

CVE-2025-53009

Back to search

CVE-2025-53009

Published: Aug 1, 2025

Modified: Aug 1, 2025

PUBLISHED

Description

MaterialX is an open standard for the exchange of rich material and look-development content across applications and renderers. In versions 1.39.2 and below, when parsing an MTLX file with multiple nested nodegraph implementations, the MaterialX XML parsing logic can potentially crash due to stack exhaustion. An attacker could intentionally crash a target program that uses OpenEXR by sending a malicious MTLX file. This is fixed in version 1.39.3.

VendorProductVersions

AcademySoftwareFoundation

MaterialX

affected
>= 1.39.2, < 1.39.3

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now