Executive brief
Open Babel is a chemical toolbox designed to speak the many languages of chemical data. A vulnerability in its SMILES format parser could allow a local attacker to cause a system crash or potentially access sensitive memory by providing a specially crafted chemical structure file. This could lead to service instability or unauthorized data exposure in applications that rely on this library for processing chemical information.
Technical details
A heap-based buffer overflow vulnerability exists in Open Babel's SMILES parser within the OBSmilesParser::ParseSmiles function located in /src/formats/smilesformat.cpp. The flaw is triggered by an out-of-bounds read on a dynamically allocated vector when processing malformed SMILES (Simplified Molecular Input Line Entry System) strings. An attacker with local access can exploit this by providing a crafted input file to an application using the library, potentially leading to a denial-of-service (crash) or information disclosure. The issue is fixed in version 3.2.0.
Affected products
- Open Babel openbabel < 3.2.0
Timeline
- 2025-09-14: disclosed: Initial bug report on GitHub with PoC
- 2025-09-26: advisory: GitHub Advisory and NVD entry published
- 2026-06-30: patched: Advisory updated to reflect fix in version 3.2.0