CVE-2025-70560

Boltz 2.0.0 contains an insecure deserialization vulnerability in its molecule loading functionality. The application uses Python pickle to deserialize molecule data files without validation. An attacker with the ability to place a malicious pickle file in a directory processed by boltz can achieve arbitrary code execution when the file is loaded.
Configurations

Configuration 1 (hide)

cpe:2.3:a:jwohlwend:boltz:2.0.0:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-02-03 18:16

Updated : 2026-06-17 10:03


NVD link : CVE-2025-70560

Mitre link : CVE-2025-70560

CVE.ORG link : CVE-2025-70560


JSON object : View

Products Affected

jwohlwend

  • boltz
CWE
CWE-502

Deserialization of Untrusted Data