boltz
Boltz
Activity
- Latest release
- 1y ago
- Total releases
- 18
- Cadence
- ~4 days
- Last 12 months
- 0
Details
- First release
- Nov 17, 2024
| Version | Released | |
|---|---|---|
2.2.1
patch
|
2.2.1
patch
Dependencies (28)
+ 20 more |
|
2.2.0
minor
|
2.2.0
minor
Dependencies (28)
+ 20 more |
|
2.1.1
patch
|
2.1.1
patch
Dependencies (28)
+ 20 more |
|
2.1.0
minor
|
2.1.0
minor
Dependencies (28)
+ 20 more |
|
2.0.3
patch
|
2.0.3
patch
Dependencies (26)
+ 18 more |
|
2.0.2
patch
|
2.0.2
patch
Dependencies (26)
+ 18 more |
|
2.0.1
patch
|
2.0.1
patch
Dependencies (26)
+ 18 more |
|
2.0.0
major
1 CVE
CVE-2025-70560
PYSEC-2026-1224
GHSA-fjm6-8xp2-4fwc
Jul 07, 2026
Boltz contains an insecure deserialization vulnerability in its molecule loading functionality
8.4
/ 10
High
Local
Low
None
None
Unchanged
High
High
High
Boltz 2.0.0 contains an insecure deserialization vulnerability in its molecule loading functionality. The application uses Python pickle to deserialize molecule data files without validation. An attacker with the ability to place a malicious pickle file in a directory processed by boltz can achieve arbitrary code execution when the file is loaded. Affected versions
0.0.0
0.1.0
0.2.0
0.2.1
0.3.0
0.3.1
0.3.2
0.4.0
0.4.1
1.0.0
2.0.0
References
Updated Jul 07, 2026 · Source: OSV.dev |
2.0.0
major
Dependencies (26)
+ 18 more |
|
1.0.0
major
1 CVE
CVE-2025-70560
PYSEC-2026-1224
GHSA-fjm6-8xp2-4fwc
Jul 07, 2026
Boltz contains an insecure deserialization vulnerability in its molecule loading functionality
8.4
/ 10
High
Local
Low
None
None
Unchanged
High
High
High
Boltz 2.0.0 contains an insecure deserialization vulnerability in its molecule loading functionality. The application uses Python pickle to deserialize molecule data files without validation. An attacker with the ability to place a malicious pickle file in a directory processed by boltz can achieve arbitrary code execution when the file is loaded. Affected versions
0.0.0
0.1.0
0.2.0
0.2.1
0.3.0
0.3.1
0.3.2
0.4.0
0.4.1
1.0.0
2.0.0
References
Updated Jul 07, 2026 · Source: OSV.dev |
1.0.0
major
Dependencies (23)
+ 15 more |
|
0.4.1
patch
1 CVE
CVE-2025-70560
PYSEC-2026-1224
GHSA-fjm6-8xp2-4fwc
Jul 07, 2026
Boltz contains an insecure deserialization vulnerability in its molecule loading functionality
8.4
/ 10
High
Local
Low
None
None
Unchanged
High
High
High
Boltz 2.0.0 contains an insecure deserialization vulnerability in its molecule loading functionality. The application uses Python pickle to deserialize molecule data files without validation. An attacker with the ability to place a malicious pickle file in a directory processed by boltz can achieve arbitrary code execution when the file is loaded. Affected versions
0.0.0
0.1.0
0.2.0
0.2.1
0.3.0
0.3.1
0.3.2
0.4.0
0.4.1
1.0.0
2.0.0
References
Updated Jul 07, 2026 · Source: OSV.dev |
0.4.1
patch
Dependencies (21)
+ 13 more |
|
0.4.0
minor
1 CVE
CVE-2025-70560
PYSEC-2026-1224
GHSA-fjm6-8xp2-4fwc
Jul 07, 2026
Boltz contains an insecure deserialization vulnerability in its molecule loading functionality
8.4
/ 10
High
Local
Low
None
None
Unchanged
High
High
High
Boltz 2.0.0 contains an insecure deserialization vulnerability in its molecule loading functionality. The application uses Python pickle to deserialize molecule data files without validation. An attacker with the ability to place a malicious pickle file in a directory processed by boltz can achieve arbitrary code execution when the file is loaded. Affected versions
0.0.0
0.1.0
0.2.0
0.2.1
0.3.0
0.3.1
0.3.2
0.4.0
0.4.1
1.0.0
2.0.0
References
Updated Jul 07, 2026 · Source: OSV.dev |
0.4.0
minor
Dependencies (21)
+ 13 more |
|
0.3.2
patch
1 CVE
CVE-2025-70560
PYSEC-2026-1224
GHSA-fjm6-8xp2-4fwc
Jul 07, 2026
Boltz contains an insecure deserialization vulnerability in its molecule loading functionality
8.4
/ 10
High
Local
Low
None
None
Unchanged
High
High
High
Boltz 2.0.0 contains an insecure deserialization vulnerability in its molecule loading functionality. The application uses Python pickle to deserialize molecule data files without validation. An attacker with the ability to place a malicious pickle file in a directory processed by boltz can achieve arbitrary code execution when the file is loaded. Affected versions
0.0.0
0.1.0
0.2.0
0.2.1
0.3.0
0.3.1
0.3.2
0.4.0
0.4.1
1.0.0
2.0.0
References
Updated Jul 07, 2026 · Source: OSV.dev |
0.3.2
patch
Dependencies (21)
+ 13 more |
|
0.3.1
patch
1 CVE
CVE-2025-70560
PYSEC-2026-1224
GHSA-fjm6-8xp2-4fwc
Jul 07, 2026
Boltz contains an insecure deserialization vulnerability in its molecule loading functionality
8.4
/ 10
High
Local
Low
None
None
Unchanged
High
High
High
Boltz 2.0.0 contains an insecure deserialization vulnerability in its molecule loading functionality. The application uses Python pickle to deserialize molecule data files without validation. An attacker with the ability to place a malicious pickle file in a directory processed by boltz can achieve arbitrary code execution when the file is loaded. Affected versions
0.0.0
0.1.0
0.2.0
0.2.1
0.3.0
0.3.1
0.3.2
0.4.0
0.4.1
1.0.0
2.0.0
References
Updated Jul 07, 2026 · Source: OSV.dev |
0.3.1
patch
Dependencies (21)
+ 13 more |
|
0.3.0
minor
1 CVE
CVE-2025-70560
PYSEC-2026-1224
GHSA-fjm6-8xp2-4fwc
Jul 07, 2026
Boltz contains an insecure deserialization vulnerability in its molecule loading functionality
8.4
/ 10
High
Local
Low
None
None
Unchanged
High
High
High
Boltz 2.0.0 contains an insecure deserialization vulnerability in its molecule loading functionality. The application uses Python pickle to deserialize molecule data files without validation. An attacker with the ability to place a malicious pickle file in a directory processed by boltz can achieve arbitrary code execution when the file is loaded. Affected versions
0.0.0
0.1.0
0.2.0
0.2.1
0.3.0
0.3.1
0.3.2
0.4.0
0.4.1
1.0.0
2.0.0
References
Updated Jul 07, 2026 · Source: OSV.dev |
0.3.0
minor
Dependencies (20)
+ 12 more |
|
0.2.1
patch
1 CVE
CVE-2025-70560
PYSEC-2026-1224
GHSA-fjm6-8xp2-4fwc
Jul 07, 2026
Boltz contains an insecure deserialization vulnerability in its molecule loading functionality
8.4
/ 10
High
Local
Low
None
None
Unchanged
High
High
High
Boltz 2.0.0 contains an insecure deserialization vulnerability in its molecule loading functionality. The application uses Python pickle to deserialize molecule data files without validation. An attacker with the ability to place a malicious pickle file in a directory processed by boltz can achieve arbitrary code execution when the file is loaded. Affected versions
0.0.0
0.1.0
0.2.0
0.2.1
0.3.0
0.3.1
0.3.2
0.4.0
0.4.1
1.0.0
2.0.0
References
Updated Jul 07, 2026 · Source: OSV.dev |
0.2.1
patch
Dependencies (20)
+ 12 more |
|
0.2.0
minor
1 CVE
CVE-2025-70560
PYSEC-2026-1224
GHSA-fjm6-8xp2-4fwc
Jul 07, 2026
Boltz contains an insecure deserialization vulnerability in its molecule loading functionality
8.4
/ 10
High
Local
Low
None
None
Unchanged
High
High
High
Boltz 2.0.0 contains an insecure deserialization vulnerability in its molecule loading functionality. The application uses Python pickle to deserialize molecule data files without validation. An attacker with the ability to place a malicious pickle file in a directory processed by boltz can achieve arbitrary code execution when the file is loaded. Affected versions
0.0.0
0.1.0
0.2.0
0.2.1
0.3.0
0.3.1
0.3.2
0.4.0
0.4.1
1.0.0
2.0.0
References
Updated Jul 07, 2026 · Source: OSV.dev |
0.2.0
minor
Dependencies (20)
+ 12 more |
|
0.1.0
minor
1 CVE
CVE-2025-70560
PYSEC-2026-1224
GHSA-fjm6-8xp2-4fwc
Jul 07, 2026
Boltz contains an insecure deserialization vulnerability in its molecule loading functionality
8.4
/ 10
High
Local
Low
None
None
Unchanged
High
High
High
Boltz 2.0.0 contains an insecure deserialization vulnerability in its molecule loading functionality. The application uses Python pickle to deserialize molecule data files without validation. An attacker with the ability to place a malicious pickle file in a directory processed by boltz can achieve arbitrary code execution when the file is loaded. Affected versions
0.0.0
0.1.0
0.2.0
0.2.1
0.3.0
0.3.1
0.3.2
0.4.0
0.4.1
1.0.0
2.0.0
References
Updated Jul 07, 2026 · Source: OSV.dev |
0.1.0
minor
Dependencies (20)
+ 12 more |
|
0.0.0
initial
1 CVE
CVE-2025-70560
PYSEC-2026-1224
GHSA-fjm6-8xp2-4fwc
Jul 07, 2026
Boltz contains an insecure deserialization vulnerability in its molecule loading functionality
8.4
/ 10
High
Local
Low
None
None
Unchanged
High
High
High
Boltz 2.0.0 contains an insecure deserialization vulnerability in its molecule loading functionality. The application uses Python pickle to deserialize molecule data files without validation. An attacker with the ability to place a malicious pickle file in a directory processed by boltz can achieve arbitrary code execution when the file is loaded. Affected versions
0.0.0
0.1.0
0.2.0
0.2.1
0.3.0
0.3.1
0.3.2
0.4.0
0.4.1
1.0.0
2.0.0
References
Updated Jul 07, 2026 · Source: OSV.dev |
0.0.0
initial
|