Junglewise Threat Intelligence

Open Babel null pointer dereference in PQSFormat::ReadMolecule

Severity: low · CVSS 3.3 · Published 2025-09-26

Technologies: Open Babel Openbabel. Vendors: PyPI.

Executive brief

Open Babel, a chemical toolbox designed to speak many languages of chemical data, is vulnerable to a crash when processing specially crafted PQS files. An attacker with local access to the system could provide a malicious file that causes the application to stop responding or crash. This primarily impacts the availability of the software for researchers and automated chemical processing pipelines.

Technical details

A vulnerability exists in Open Babel versions prior to 3.2.0 within the PQSFormat::ReadMolecule function in /src/formats/PQSformat.cpp. The issue stems from a null pointer dereference (or out-of-bounds read) when the lowerit(char*) function is called with an unvalidated pointer during string parsing of PQS format files. An attacker can exploit this by providing a crafted input file to a local instance of Open Babel, resulting in a segmentation fault and application crash. The vulnerability was identified via fuzzing and has been addressed in version 3.2.0.

Affected products

  • Open Babel openbabel < 3.2.0

Timeline

  • 2025-09-14: disclosed: Issue reported on GitHub with PoC
  • 2025-09-26: advisory: Initial GHSA and NVD publication
  • 2026-07-01: patched: Advisory updated to reflect fix in version 3.2.0

References

Related threats