Executive brief
Open Babel is a widely used software library for converting and viewing chemical data files. A security vulnerability in how it handles certain file formats allows an attacker to execute malicious code by tricking the system into processing a specially crafted file. This could lead to a complete system takeover, data theft, or service disruption, especially for web-based chemical conversion services that use this library in their backend.
Technical details
An out-of-bounds write vulnerability (CWE-787) exists in the PQS format coord_file parser within Open Babel. The root cause is an unsafe 'strcat' operation in 'formats/PQSformat.cpp' where a user-controlled string from a 'file=' parameter is concatenated to a fixed-size stack buffer ('full_coord_path') without sufficient bounds checking. An attacker can exploit this by providing a malformed PQS file, leading to a stack-based buffer overflow. While typically a local file-parsing issue, the vulnerability is rated critical (CVSS 9.8) because Open Babel is frequently used in networked backend services for automated chemical format conversion. The issue is patched in version 3.2.0.
Affected products
- Open Babel Open Babel 3.1.1, master commit 530dbfa3, and all versions prior to 3.2.0
Timeline
- 2023-07-21: advisory: Initial advisory published by Talos and GitHub
- 2026-07-01: other: Advisory withdrawn as a duplicate of GHSA-f29h-2h58-48r7