© 2025-2026 PySpect
First version without a known vulnerability: 2.6.6
pytorch-lightning vulnerable to Arbitrary File Write via /v1/runs API endpoint
Fixed in: 2.3.3
Remote code execution in pytorch lightning
Fixed in: 2.3.3
PyTorch Lightning through 2.6.5, fixed in commit d710d68, contains a remote code execution vulnerability in the _load_state function that imports and executes attacker-controlled module names from checkpoint _instantiator hyperparameters. Attackers can craft malicious checkpoint files that bypass weights_only=True protections to execute arbitrary code when LightningModule.load_from_checkpoint is called.
Fixed in: 2.6.6
PyTorch Lightning load_from_checkpoint has an insecure checkpoint deserialization
Compromise of PyTorch Lightning PyPi Package Versions
Fixed in: 2.6.4
PyTorch Lightning denial of service vulnerability
PyTorch Lightning path traversal vulnerability
Fixed in: 2.4.0
Code Injection in PyTorch Lightning
Fixed in: 1.6.0, 8b7a12c52e52a06408e9231647839ddb4665e8ae
pytorch-lightning is vulnerable to Deserialization of Untrusted Data
Fixed in: 1.6.0, 62f1e82e032eb16565e676d39e0db0cac7e34ace