Wow this sure is overstated. The biggest actual risk here is ISPs doing deep inspection and getting data from private trackers.
Not nothing, but the ‘RCE’ they are claiming relies on an edge case and a lot of manual work on the part of a potential attacker who would also need to be able to intercept your traffic on the off chance you run qbit on windows and use qbit to install python.
This, to me, is a big nothing burger.
I have a T430 that still sees use as an occasional web browsing & Arduino coding machine. I bought it used in 2016 without HDD for $150, and I don’t think I’ve gotten better value for money with any of my other computer purchases to-date.