Junglewise Threat Intelligence

CVE-2025-10994: Open Babel use-after-free in GAMESSOutputFormat::ReadMolecule

CVE-2025-10994 · Severity: high · CVSS 7.8 · Published 2026-06-30

Technologies: openbabel (PyPI), Open Babel. Vendors: PyPI.

Executive brief

Open Babel, a widely used chemistry data toolkit, contains a memory safety flaw in its GAMESS file parser. If a user or automated service processes a specially crafted chemistry file, it could lead to a program crash or potentially allow an attacker to execute unauthorized code. This affects researchers and organizations using the software to convert or analyze molecular data.

Technical details

A use-after-free vulnerability exists in the `GAMESSOutputFormat::ReadMolecule` function within `gamessformat.cpp`. The flaw is triggered when parsing a malformed GAMESS output file, causing the parser to dereference a stale pointer after the underlying memory object has been freed. An attacker can exploit this by providing a crafted input file to the `obabel` CLI tool, the `OBConversion` API, or any of its language bindings (Python, Java, etc.). Successful exploitation could lead to memory corruption, application crashes, or remote code execution in the context of the application. The issue was identified via OSS-Fuzz and is resolved in version 3.2.0.

Affected products

  • Open Babel Open Babel <= 3.1.1

Timeline

  • 2025-09-14: disclosed: Initial bug report on GitHub issue tracker
  • 2026-05-26: patched: Version 3.2.0 released with fix
  • 2026-06-30: advisory: GitHub Advisory published

References

Related threats