Executive brief
OriginPro is a scientific graphing and data analysis application used by researchers and engineers. A flaw in how it processes OGG project files could allow an attacker to execute arbitrary code if a user opens a malicious file, potentially compromising sensitive research data and system access with the user's privileges.
Technical details
The vulnerability is an out-of-bounds write in OriginPro's OGG file parser, resulting from insufficient validation of user-supplied data structures. An attacker can craft a malicious OGG project file that triggers a write past the end of an allocated buffer during parsing, causing memory corruption. Exploitation requires user interaction (opening a malicious OGG file), but if successful allows arbitrary code execution in the context of the current user. The issue affects OriginPro 2026b SR0 and earlier; a patch is available in OriginPro 2026b SR1.
Affected products
- OriginLab OriginPro 2026b SR0 and earlier
Timeline
- 2026-04-08: disclosed: Vulnerability reported to vendor
- 2026-08-11: advisory: Coordinated public release of advisory
- 2026-08-11: patched: Fix available in OriginPro 2026b SR1