Amazon Braket SDK Vulnerability Lets Attackers Execute Code via Job Results
Amazon Braket SDK versions 1.10.0 through 1.116.x have a nasty insecure deserialization flaw (CVE-2026-9291) in job results processing. If you've got S3 write access to the output bucket, you can swap the dataFormat field and inject malicious pickle payloads—boom, arbitrary code execution on anyone processing those results. Update to 1.117.0+ immediately if you're using this quantum computing SDK.
source: [aws/security-bulletin]