Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
5.3
Open Babel CDXML File Handler Allows Remote Code Execution
CVE-2026-3408
Summary
A vulnerability in Open Babel's CDXML File Handler could allow an attacker to execute malicious code remotely. This is a serious issue because it could be exploited by someone with malicious intent. Updating to a patched version of Open Babel is recommended to prevent potential harm.
What to do
No fix is available yet. Check with your software vendor for updates.
Affected software
| Vendor | Product | Affected versions | Fix available |
|---|---|---|---|
| openbabel | open_babel | <= 3.1.1 | – |
Original title
A vulnerability was identified in Open Babel up to 3.1.1. This impacts the function OBAtom::GetExplicitValence of the file isrc/atom.cpp of the component CDXML File Handler. Such manipulation leads...
Original description
A vulnerability was identified in Open Babel up to 3.1.1. This impacts the function OBAtom::GetExplicitValence of the file isrc/atom.cpp of the component CDXML File Handler. Such manipulation leads to null pointer dereference. The attack can be launched remotely. The exploit is publicly available and might be used. The name of the patch is e23a224b8fd9d7c2a7cde9ef4ec6afb4c05aa08a. It is best practice to apply a patch to resolve this issue.
nvd CVSS2.0
5.0
nvd CVSS3.1
6.5
nvd CVSS4.0
5.3
Vulnerability type
CWE-404
CWE-476
NULL Pointer Dereference
CWE-787
Out-of-bounds Write
- https://github.com/VedantMadane/openbabel/commit/e23a224b8fd9d7c2a7cde9ef4ec6afb... Patch
- https://github.com/oneafter/0128/blob/main/ob3/repro.cdxml Issue Tracking
- https://github.com/openbabel/openbabel/issues/2848 Exploit Issue Tracking
- https://github.com/openbabel/openbabel/pull/2862 Issue Tracking
- https://vuldb.com/?ctiid.348303 Permissions Required VDB Entry
- https://vuldb.com/?id.348303 Third Party Advisory VDB Entry
- https://vuldb.com/?submit.763756 Third Party Advisory VDB Entry
Published: 2 Mar 2026 · Updated: 13 Mar 2026 · First seen: 6 Mar 2026