Executive brief
OriginPro is a data analysis and visualization software suite used by researchers and engineers. A flaw in how it parses project files (.OPJ) allows attackers to execute arbitrary code if a user opens a malicious project file. This could lead to full compromise of the user's system and access to sensitive data or intellectual property.
Technical details
The vulnerability is an out-of-bounds write (buffer overflow) in the OPJ file parsing logic caused by insufficient validation of user-supplied data. Attack vector is local with user interaction required—the victim must open a specially crafted OPJ file. An attacker can leverage this to execute arbitrary code in the context of the current user. The vulnerability affects OriginPro versions 2026b SR0 and earlier; a fix is available in version 2026b SR1 and later.
Affected products
- OriginLab OriginPro 2026b SR0 and earlier
Timeline
- 2026-08-11: disclosed
- 2026-08-20: patched: Fixed in OriginPro 2026b SR1