⚠ Withdrawn by GitHub Security Advisories
Withdrawn: July 1, 2026
GHSA-4r3q-94wc-xhq9CriticalCVSS 9.8Disclosed before NVD
Duplicate Advisory: Open Babel has out-of-bounds write in MOPAC translationVectors[] (FINAL POINT)
📋 Description
Duplicate Advisory
This advisory has been withdrawn because it is a duplicate of GHSA-7h6r-6p76-68c9. This link is maintained to preserve external references.
Original Description
Multiple out-of-bounds write vulnerabilities exist in the translationVectors parsing functionality in multiple supported formats of Open Babel 3.1.1 and master commit 530dbfa3. A specially-crafted malformed file can lead to arbitrary code execution. An attacker can provide a malicious file to trigger this vulnerability.This vulnerability affects the MOPAC file format, inside the Final Point and Derivatives section
🎯 Affected products1
- pip/openbabel:< 3.2.0