Vulnerabilities
Vulnerable Software
Ibm:  >> Qiskit  Security Vulnerabilities
A maliciously crafted QPY file can potential execute arbitrary-code embedded in the payload without privilege escalation when deserialising QPY formats < 13. A python process calling Qiskit 0.18.0 through 1.4.1's `qiskit.qpy.load()` function could potentially execute any arbitrary Python code embedded in the correct place in the binary file as part of specially constructed payload.
CVSS Score
9.8
EPSS Score
0.002
Published
2025-03-14
Qiskit SDK 0.45.0 through 1.2.4 could allow a remote attacker to cause a denial of service using a maliciously crafted QPY file containing a malformed symengine serialization stream which can cause a segfault within the symengine library.
CVSS Score
8.6
EPSS Score
0.003
Published
2025-02-21


Contact Us

Shodan ® - All rights reserved