The fix is straightforward, but the risk model is not: when a library parses untrusted 3D content, a single bug can turn a routine import into a code-execution path.