Executive brief
Open Babel, a widely used chemistry data conversion library, contains a memory safety flaw in its GRO file format parser. If a user or automated service processes a specially crafted chemistry file, it could lead to a program crash or potentially allow an attacker to execute unauthorized code. This affects researchers and organizations using Open Babel to handle untrusted molecular data files.
Technical details
A memory-safety vulnerability (CWE-824) exists in Open Babel's GRO reader due to improper residue handling. A malformed record in a GRO file causes the parser to access a residue pointer that has not been initialized. Exploitation requires a victim to open a crafted GRO file using the 'obabel' CLI tool, the OBConversion API, or any of the supported language bindings (Python, Java, etc.). While primarily leading to a denial-of-service (crash), some reports suggest it could potentially lead to arbitrary code execution. The issue is fixed in version 3.2.0.
Affected products
- Open Babel Open Babel <= 3.1.1
Timeline
- 2026-05-26: patched: Version 3.2.0 released
- 2026-07-01: advisory: GitHub Advisory published
References
- https://github.com/openbabel/openbabel/security/advisories/GHSA-mw5r-wq2m-397c
- https://github.com/openbabel/openbabel/commit/fa9a2d9a2eb75154b7a884dfe679ff41a8f9c547
- https://talosintelligence.com/vulnerability_reports/TALOS-2022-1668
- https://www.talosintelligence.com/vulnerability_reports/TALOS-2022-1668
- https://api.github.com/repos/openbabel/openbabel/security-advisories/GHSA-mw5r-wq2m-397c