PT-2026-6414 · Pypi · Boltz

Published

2026-02-03

·

Updated

2026-02-03

CVSS v3.1

8.4

High

VectorAV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Boltz 2.0.0 contains an insecure deserialization vulnerability in its molecule loading functionality. The application uses Python pickle to deserialize molecule data files without validation. An attacker with the ability to place a malicious pickle file in a directory processed by boltz can achieve arbitrary code execution when the file is loaded.

Fix

Deserialization of Untrusted Data

Weakness Enumeration

Related Identifiers

GHSA-FJM6-8XP2-4FWC

Affected Products

Boltz