Executive brief
Open Babel is a widely used software library for converting and processing chemical data files. A security flaw in its ChemKin file parser allows an attacker to crash the application or potentially execute unauthorized code if a user is tricked into opening a specially crafted, malicious chemistry file. This affects researchers and organizations using Open Babel's command-line tools or integrated services in various programming languages like Python, Java, and C#.
Technical details
A heap-based buffer overflow exists in Open Babel versions up to and including 3.1.1 within the ChemKinFormat::CheckSpecies function in src/formats/chemkinformat.cpp. The vulnerability is triggered when the parser encounters a malformed species record in a ChemKin file, leading to an out-of-bounds write on the heap during a std::map::find operation or string manipulation. An attacker can exploit this by providing a crafted ChemKin file to the obabel CLI tool or any application using the OBConversion API. The issue was identified via OSS-Fuzz and is addressed in version 3.2.0.
Affected products
- Open Babel openbabel <= 3.1.1
Timeline
- 2025-09-14: disclosed: Original bug report on GitHub issue #2830
- 2026-05-26: patched: Version 3.2.0 released with fix
- 2026-07-01: advisory: GitHub Advisory published