CVE-2025-2000: CWE-502 Deserialization of Untrusted Data in IBM Qiskit SDK
A maliciously crafted QPY file can potential execute arbitrary-code embedded in the payload without privilege escalation when deserialising QPY formats < 13. A python process calling Qiskit 0.18.0 through 1.4.1's `qiskit.qpy.load()` function could potentially execute any arbitrary Python code embedded in the correct place in the binary file as part of specially constructed payload.
CVE-2025-2000: CWE-502 Deserialization of Untrusted Data in IBM Qiskit SDK
Description
A maliciously crafted QPY file can potential execute arbitrary-code embedded in the payload without privilege escalation when deserialising QPY formats < 13. A python process calling Qiskit 0.18.0 through 1.4.1's `qiskit.qpy.load()` function could potentially execute any arbitrary Python code embedded in the correct place in the binary file as part of specially constructed payload.
Technical Details
- Data Version
- 5.1
- Assigner Short Name
- ibm
- Date Reserved
- 2025-03-05T16:10:36.949Z
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 6883ae32ad5a09ad00530b6b
Added to database: 7/25/2025, 4:17:54 PM
Last updated: 7/25/2025, 4:17:54 PM
Views: 1
Related Threats
CVE-2025-3508: CWE-200 Exposure of Sensitive Information to an Unauthorized Actor in HP Inc. Certain HP DesignJet products
MediumCVE-2025-3873: CWE-787 Out-of-bounds Write in silabs.com WiseConnect
MediumCVE-2025-34139: Vulnerability in Sitecore Experience Manager (XM)
HighCVE-2025-34138: Vulnerability in Sitecore Experience Manager (XM)
CriticalCVE-2025-34114: CWE-749 Exposed Dangerous Method or Function in Laser Romae s.r.l. OpenBlow
HighActions
External Links
Need enhanced features?
Contact root@offseq.com for Pro access with improved analysis and higher rate limits.