PT-2026-60248 · Pypi · Pytorch-Lightning
CVSS v4.0
8.4
High
| Vector | AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
PyTorch Lightning versions prior to 2.6.6
Description
A remote code execution issue exists in the
load state function. The flaw allows the import and execution of attacker-controlled module names from checkpoint instantiator hyperparameters. An attacker can create malicious checkpoint files that bypass weights only=True protections to execute arbitrary code when the load from checkpoint function of LightningModule is called.Recommendations
Update PyTorch Lightning to version 2.6.6 or later.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Pytorch-Lightning