{"id":"CVE-2025-2000","details":"A maliciously crafted QPY file can potential execute arbitrary-code embedded in the payload without privilege escalation when deserialising QPY formats \u003c 13. A python process calling Qiskit 0.18.0 through 1.4.1's `qiskit.qpy.load()` function could potentially execute any arbitrary Python code embedded in the correct place in the binary file as part of specially constructed payload.","aliases":["GHSA-6m2c-76ff-6vrf","PYSEC-2026-510","PYSEC-2026-511"],"modified":"2026-07-09T18:18:31.289949Z","published":"2025-03-14T13:15:40.907Z","references":[{"type":"ADVISORY","url":"https://www.ibm.com/support/pages/node/7185949"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/qiskit/qiskit","events":[{"introduced":"5ca967557b21828c0760763b7f0c5870e5f032d9"},{"fixed":"3da3d5ad37dd0b255ab83582d43ff7ee33fa9edf"}],"database_specific":{"cpe":"cpe:2.3:a:ibm:qiskit:*:*:*:*:*:php:*:*","extracted_events":[{"introduced":"0.18.0"},{"fixed":"1.4.2"}],"source":"CPE_RANGE"}}],"versions":["1.4.1","1.4.0","1.3.0","1.3.0rc2","1.3.0rc1","1.3.0b1","1.1.0rc1","1.0.0rc1","1.0.0b1","0.45.0rc1","0.25.0rc1","0.24.0rc1","0.23.0rc1","0.22.0rc1","0.21.0rc1","0.20.0","0.19.0","0.18.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-2000.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}