PyPi: Qiskit-Ibm-Runtime

CVE-2024-29032

Safety vulnerability ID: 71930

This vulnerability was reviewed by experts

The information on this page was manually curated by our Cybersecurity Intelligence Team.

Created at Mar 20, 2024 Updated at Nov 11, 2024
Scan your Python projects for vulnerabilities →

Advisory

A vulnerability has been identified in qiskit_ibm_runtime.RuntimeDecoder where deserializing JSON data can lead to arbitrary code execution. The RuntimeDecoder is intended to deserialize JSON strings that contain various special types encoded via RuntimeEncoder. However, an attacker can craft a malicious payload that causes the decoder to spawn a subprocess and execute arbitrary code.

Affected package

qiskit-ibm-runtime

Latest version: 0.33.2

IBM Quantum client for Qiskit Runtime.

Affected versions

Fixed versions

Vulnerability changelog

This vulnerability has no description

Resources

Use this package?

Scan your Python project for dependency vulnerabilities in two minutes

Scan your application