© 2025-2026 PySpect
First version without a known vulnerability: 2.6.6
PyTorch Lightning load_from_checkpoint has an insecure checkpoint deserialization
Compromise of PyTorch Lightning PyPi Package Versions
Fixed in: 2.6.4
pytorch-lightning is vulnerable to Deserialization of Untrusted Data
Fixed in: 62f1e82e032eb16565e676d39e0db0cac7e34ace, 1.6.0
PyTorch Lightning denial of service vulnerability
Code Injection in GitHub repository pytorchlightning/pytorch-lightning prior to 1.6.0.
Fixed in: 8b7a12c52e52a06408e9231647839ddb4665e8ae, 1.6.0
PyTorch Lightning path traversal vulnerability
Fixed in: 2.4.0
PyTorch Lightning allows arbitrary code execution through checkpoint _instantiator hyperparameters
Fixed in: 2022.6.15, 2.6.6
Malicious code in lightning (PyPI)
pytorch-lightning vulnerable to Arbitrary File Write via /v1/runs API endpoint
Fixed in: 2.3.3
Remote code execution in pytorch lightning
Fixed in: 2.3.3