Back

CRITICAL

Qiskit SDK code execution

Published Mar 14, 2025

Description

A maliciously crafted QPY file can potential execute arbitrary-code embedded in the payload without privilege escalation when deserialising QPY formats < 13. A python process calling Qiskit 0.18.0 through 1.4.1's `qiskit.qpy.load()` function could potentially execute any arbitrary Python code embedded in the correct place in the binary file as part of specially constructed payload.

Affected products

Remediation

Vendor solution

Upgrade to Qiskit 1.4.2 or Qiskit 2.0.0, see: https://pypi.org/project/qiskit/ for the latest versions.

Metrics

References (4)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner ibm
Published Mar 14, 2025
Updated Feb 26, 2026
Reserved Mar 5, 2025
CISA Vulnrichment
Updated Mar 15, 2025
NVD
Status Analyzed
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a
GHSA-6M2C-76FF-6VRF