qiskit-ibm-runtime@0.19.0 vulnerabilities

IBM Quantum client for Qiskit Runtime.

Direct Vulnerabilities

Known vulnerabilities in the qiskit-ibm-runtime package. This does not include vulnerabilities belonging to this package’s dependencies.

Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.
Fix for free
Vulnerability Vulnerable Version
  • M
Deserialization of Untrusted Data

qiskit-ibm-runtime is an IBM Quantum client for Qiskit Runtime.

Affected versions of this package are vulnerable to Deserialization of Untrusted Data due to the deserialization of JSON data using a specifically crafted input string. An attacker can execute arbitrary code on the system by providing a maliciously formatted input string to the deserialization process.

How to fix Deserialization of Untrusted Data?

Upgrade qiskit-ibm-runtime to version 0.21.2 or higher.

[0.1.0,0.21.2)