Executive brief
Open Babel is a widely used software library for converting and processing chemistry data files. A vulnerability in its MOPAC file parser allows a specially crafted file to cause a memory error when opened. This could lead to a program crash or potentially allow an attacker to execute unauthorized code on the system where the file is processed.
Technical details
An out-of-bounds (OOB) write vulnerability exists in the MOPAC input parser of Open Babel. The root cause is the use of a fixed-size array, `translationVectors[]`, which is designed to hold a maximum of three translation vectors. When parsing a malformed MOPAC file containing more than three Tv atoms, the parser continues to write data beyond the array's allocated memory. This memory corruption can be triggered via the `obabel` CLI tool, the `OBConversion` API, or any of the library's language bindings (Python, Java, etc.). Successful exploitation requires a user to open a malicious file and can lead to arbitrary code execution or a denial-of-service. The issue is addressed in version 3.2.0 by adding bounds checking to ensure no more than three vectors are written.
Affected products
- Open Babel openbabel <= 3.1.1
Timeline
- 2026-05-09: other: Fix commit authored
- 2026-05-26: patched: Version 3.2.0 released
- 2026-07-01: advisory: GitHub Advisory published
References
- https://github.com/openbabel/openbabel/security/advisories/GHSA-mjmg-352j-f456
- https://github.com/openbabel/openbabel/commit/40e852138f21d586b7ccdce6329e7b23a87168bb
- https://talosintelligence.com/vulnerability_reports/TALOS-2022-1666
- https://www.talosintelligence.com/vulnerability_reports/TALOS-2022-1666
- https://api.github.com/repos/openbabel/openbabel/security-advisories/GHSA-mjmg-352j-f456