{"id":"GHSA-grjp-54v3-c442","aliases":[],"url":"https://o3.security/vulnerability/GHSA-grjp-54v3-c442","summary":"OpenUSD File Parsing Use-After-Free Remote Code Execution Vulnerability","details":"# Patch\nThis is fixed with [commit b953092](https://github.com/PixarAnimationStudios/OpenUSD/commit/b9530922b6a8ea72cd43661226b693fff8abbe4c), with the fix available in OpenUSD 25.11 and onwards.\n\n# Summary\nWe have been advised by Zero Day Initiative that our usage of the USD framework may constitute a Use-After-Free Remote Code Execution Vulnerability. They have sent us the attached file illustrating the issue. Indeed, we see a use after free exception when running the file through our importer with an address sanitizer.\n\n[zdi-23709-poc0.zip](https://github.com/user-attachments/files/17474297/zdi-23709-poc0.zip)\n\nThanks in advance.","published":"2025-10-29T22:13:03Z","modified":"2025-10-29T22:31:30.040308Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"PyPI","name":"usd-core","fixedVersion":"25.11"}],"fix":{"url":"https://github.com/PixarAnimationStudios/OpenUSD/commit/b9530922b6a8ea72cd43661226b693fff8abbe4c","label":"PixarAnimationStudios/OpenUSD@b953092"},"references":[{"type":"WEB","url":"https://github.com/PixarAnimationStudios/OpenUSD/security/advisories/GHSA-grjp-54v3-c442"},{"type":"WEB","url":"https://github.com/PixarAnimationStudios/OpenUSD/commit/b9530922b6a8ea72cd43661226b693fff8abbe4c"},{"type":"PACKAGE","url":"https://github.com/PixarAnimationStudios/OpenUSD"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2025-10-29T22:31:30.040308Z"}}