Vulnerability Description
A maliciously crafted QPY file can potential execute arbitrary-code embedded in the payload without privilege escalation when deserialising QPY formats < 13. A python process calling Qiskit 0.18.0 through 1.4.1's `qiskit.qpy.load()` function could potentially execute any arbitrary Python code embedded in the correct place in the binary file as part of specially constructed payload.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ibm | Qiskit | >= 0.18.0, < 1.4.2 |
Related Weaknesses (CWE)
References
- https://www.ibm.com/support/pages/node/7185949Vendor Advisory
FAQ
What is CVE-2025-2000?
CVE-2025-2000 is a vulnerability with a CVSS score of 9.8 (CRITICAL). A maliciously crafted QPY file can potential execute arbitrary-code embedded in the payload without privilege escalation when deserialising QPY formats < 13. A python process calling Qiskit 0.18.0 thr...
How severe is CVE-2025-2000?
CVE-2025-2000 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2025-2000?
Check the references section above for vendor advisories and patch information. Affected products include: Ibm Qiskit.