VendorsLightning AIpytorch_lightningall versions
Vulnerabilities

Lightning AI PyTorch Lightning

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

9CVEs
CVE-2022-0845
Code Injection in pytorchlightning/pytorch-lightning
Published 2022-03-05 · Modified
10.0EPSS 0.010
CVE-2024-5452
RCE via Property/Class Pollution in lightning-ai/pytorch-lightning
Published 2024-06-06 · Modified
9.8EPSS 0.268
CVE-2024-5980
Arbitrary File Write via /v1/runs API endpoint in lightning-ai/pytorch-lightning
Published 2024-06-27 · Modified
9.8EPSS 0.013
CVE-2026-44484
Compromise of PyTorch Lightning PyPi Package Versions
Published 2026-05-14 · Modified
9.8EPSS 0.007
CVE-2024-8019
Arbitrary File Write/Overwrite in lightning-ai/pytorch-lightning
Published 2025-03-20 · Analyzed
9.1EPSS 0.011
CVE-2026-31221
PyTorch-Lightning versions 2.6.0 and earlier contain an insecure deserialization vulnerability (CWE-502) in the checkpoint loading mechanism. The LightningModule.load_from_checkpoint() method, which is commonly used to load saved model states, internally calls torch.load() without setting the security-restrictive weights_only=True parameter. This default behavior allows the deserialization of arbitrary Python objects via the Pickle module. A remote attacker can exploit this by providing a maliciously crafted checkpoint file, leading to arbitrary code execution on the victim's system when the file is loaded.
Published 2026-05-12 · Modified
8.8EPSS 0.006
CVE-2026-58659
PyTorch Lightning Arbitrary Code Execution via _instantiator Hyperparameter
Published 2026-07-15 · Analyzed
8.4EPSS 0.006
CVE-2021-4118
Deserialization of Untrusted Data in pytorchlightning/pytorch-lightning
Published 2021-12-23 · Modified
7.8EPSS 0.010
CVE-2024-8020
Denial of Service in lightning-ai/pytorch-lightning
Published 2025-03-20 · Modified
7.5EPSS 0.006