Executive brief
Open Babel, a chemical toolbox designed to speak many languages of chemical data, is vulnerable to a crash when processing specially crafted PQS files. An attacker with local access to the system could provide a malicious file that causes the application to stop responding or crash. This primarily impacts the availability of the software for researchers and automated chemical processing pipelines.
Technical details
A vulnerability exists in Open Babel versions prior to 3.2.0 within the PQSFormat::ReadMolecule function in /src/formats/PQSformat.cpp. The issue stems from a null pointer dereference (or out-of-bounds read) when the lowerit(char*) function is called with an unvalidated pointer during string parsing of PQS format files. An attacker can exploit this by providing a crafted input file to a local instance of Open Babel, resulting in a segmentation fault and application crash. The vulnerability was identified via fuzzing and has been addressed in version 3.2.0.
Affected products
- Open Babel openbabel < 3.2.0
Timeline
- 2025-09-14: disclosed: Issue reported on GitHub with PoC
- 2025-09-26: advisory: Initial GHSA and NVD publication
- 2026-07-01: patched: Advisory updated to reflect fix in version 3.2.0