Junglewise Threat Intelligence

Open Babel heap buffer overflow in ChemKinFormat::CheckSpecies

Severity: medium · CVSS 5.3 · Published 2025-09-26

Technologies: Open Babel Openbabel. Vendors: PyPI.

Executive brief

Open Babel, a chemical toolbox used to search, convert, and analyze chemical data, is vulnerable to a memory corruption flaw. An attacker with local access to a system could provide a specially crafted chemical data file to trigger a crash or potentially execute unauthorized code. This could lead to a loss of data confidentiality, integrity, or system availability.

Technical details

A heap-based buffer overflow exists in Open Babel versions prior to 3.2.0 within the ChemKinFormat::CheckSpecies function in /src/formats/chemkinformat.cpp. The vulnerability is triggered when the library processes malformed ChemKin format input files, where an unchecked or malformed string is used as a lookup key in a std::map::find call, leading to an out-of-bounds read/write. An attacker with local access can exploit this by providing a crafted file to a tool using the Open Babel library (e.g., fuzz_convert). While NVD and VulDB provide varying CVSS scores, the NVD assessment indicates a high severity (7.8) due to potential impacts on confidentiality, integrity, and availability. The issue is addressed in version 3.2.0.

Affected products

  • Open Babel openbabel < 3.2.0

Timeline

  • 2025-09-14: disclosed: Initial bug report on GitHub issue tracker
  • 2025-09-26: advisory: GitHub and NVD advisories published
  • 2026-07-01: patched: Advisory updated to reflect fix in version 3.2.0

References

Related threats