Skip to main content

CVE-2025-2000: CWE-502 Deserialization of Untrusted Data in IBM Qiskit SDK

Critical
VulnerabilityCVE-2025-2000cvecve-2025-2000cwe-502
Published: Fri Mar 14 2025 (03/14/2025, 13:04:46 UTC)
Source: CVE Database V5
Vendor/Project: IBM
Product: Qiskit SDK

Description

A maliciously crafted QPY file can potential execute arbitrary-code embedded in the payload without privilege escalation when deserialising QPY formats < 13. A python process calling Qiskit 0.18.0 through 1.4.1's `qiskit.qpy.load()` function could potentially execute any arbitrary Python code embedded in the correct place in the binary file as part of specially constructed payload.

Technical Details

Data Version
5.1
Assigner Short Name
ibm
Date Reserved
2025-03-05T16:10:36.949Z
Cvss Version
3.1
State
PUBLISHED

Threat ID: 6883ae32ad5a09ad00530b6b

Added to database: 7/25/2025, 4:17:54 PM

Last updated: 7/25/2025, 4:17:54 PM

Views: 1

Actions

Please log in to the Console to use AI analysis features.

Need enhanced features?

Contact root@offseq.com for Pro access with improved analysis and higher rate limits.

Latest Threats