CVE-2025-70560

Boltz 2.0.0 contains an insecure deserialization vulnerability in its molecule loading functionality. The application uses Python pickle to deserialize molecule data files without validation. An attacker with the ability to place a malicious pickle file in a directory processed by boltz can achieve arbitrary code execution when the file is loaded.
Configurations

Configuration 1 (hide)

cpe:2.3:a:jwohlwend:boltz:2.0.0:*:*:*:*:*:*:*

History

17 Jun 2026, 10:03

Type Values Removed Values Added
Summary
  • (es) Boltz 2.0.0 contiene una vulnerabilidad de deserialización insegura en su funcionalidad de carga de moléculas. La aplicación utiliza Python pickle para deserializar archivos de datos de moléculas sin validación. Un atacante con la capacidad de colocar un archivo pickle malicioso en un directorio procesado por boltz puede lograr ejecución de código arbitrario cuando el archivo es cargado.

19 Feb 2026, 15:16

Type Values Removed Values Added
References
  • () https://github.com/advisories/GHSA-fjm6-8xp2-4fwc -

11 Feb 2026, 16:01

Type Values Removed Values Added
References () https://github.com/jwohlwend/boltz/blob/cb04aeccdd480fd4db707f0bbafde538397fa2ac/src/boltz/data/mol.py#L80 - () https://github.com/jwohlwend/boltz/blob/cb04aeccdd480fd4db707f0bbafde538397fa2ac/src/boltz/data/mol.py#L80 - Product
References () https://github.com/jwohlwend/boltz/issues/600 - () https://github.com/jwohlwend/boltz/issues/600 - Issue Tracking
First Time Jwohlwend boltz
Jwohlwend
CPE cpe:2.3:a:jwohlwend:boltz:2.0.0:*:*:*:*:*:*:*

04 Feb 2026, 15:16

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 8.4
CWE CWE-502

03 Feb 2026, 18:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-02-03 18:16

Updated : 2026-06-17 10:03


NVD link : CVE-2025-70560

Mitre link : CVE-2025-70560

CVE.ORG link : CVE-2025-70560


JSON object : View

Products Affected

jwohlwend

  • boltz
CWE
CWE-502

Deserialization of Untrusted Data