CVE-2025-2000 | IBM Qiskit SDK up to 1.4.1 QPY Format qiskit.qpy.load deserialization
A vulnerability was found in IBM Qiskit SDK up to 1.4.1. It has been declared as very critical. Affected by this vulnerability is the function qiskit.qpy.load of the component QPY Format Handler. The manipulation leads to deserialization.
This vulnerability is known as CVE-2025-2000. The attack can be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.