PT-2026-60248 · Pypi · Pytorch-Lightning

·

CVE-2026-58659

·

Published

2026-07-15

·

Updated

2026-07-20

CVSS v4.0

8.4

High

VectorAV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions PyTorch Lightning versions prior to 2.6.6
Description A remote code execution issue exists in the load state function. The flaw allows the import and execution of attacker-controlled module names from checkpoint instantiator hyperparameters. An attacker can create malicious checkpoint files that bypass weights only=True protections to execute arbitrary code when the load from checkpoint function of LightningModule is called.
Recommendations Update PyTorch Lightning to version 2.6.6 or later.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-58659
PYSEC-2026-3624

Affected Products

Pytorch-Lightning