Executive brief
OriginPro is a data analysis and graphing software used by scientists and engineers. A flaw in how it parses OPJU project files allows attackers to trigger an out-of-bounds write that corrupts memory. If a user opens a specially crafted malicious project file, an attacker can execute arbitrary code with the privileges of that user, potentially compromising their system and data.
Technical details
The vulnerability is an out-of-bounds write in the OPJU file parser, caused by insufficient validation of user-supplied data during file processing. The attack vector is local with user interaction required—a target must open a malicious OPJU project file. This results in heap corruption that can be leveraged to achieve remote code execution in the context of the current process. The vulnerability affects OriginPro 2026b SR0 and earlier; OriginLab released a fix in OriginPro 2026b SR1.
Affected products
- OriginLab OriginPro 2026b SR0 and earlier
Timeline
- 2026-03-11: disclosed: Vulnerability reported to vendor
- 2026-08-11: patched: Coordinated public release; fix available in OriginPro 2026b SR1