PT-2026-5024 · Facebook · Pytorch

·

CVE-2026-24747

·

Published

2025-09-17

·

Updated

2026-07-07

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions PyTorch versions prior to 2.10.0
Description PyTorch, a Python package for tensor computation, has an issue in its weights only unpickler. An attacker can create a malicious checkpoint file (.pth) that, when loaded using torch.load(..., weights only=True), can cause memory corruption and potentially lead to arbitrary code execution. The vulnerability stems from improper validation of pickle opcodes and storage metadata within the weights only=True unpickler, specifically related to heap memory corruption via SETITEM/SETITEMS opcodes applied to non-dictionary types and storage size mismatches. The vulnerability is fully weaponized and can lead to remote code execution on any service that supports uploading and running a PyTorch model, even with security hardening.
Recommendations Versions prior to 2.10.0 should be updated to version 2.10.0 or later.

Exploit

Fix

RCE

Deserialization of Untrusted Data

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-75293
AZL-75588
BDU:2026-01224
BIT-PYTORCH-2026-24747
CVE-2026-24747
ECHO-B294-6932-072F
GHSA-63CW-57P8-FM3P
PYSEC-2026-1856
PYSEC-2026-2286

Affected Products

Pytorch