CVE-2022-0845Critical· 9.8▾ MidnightCode Injection in PyTorch Lightning
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 53.9 · likelihood 0.2 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Sep 12.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
1.0%
PyTorch Lightning version 1.5.10 and prior is vulnerable to code injection. An attacker could execute commands on the target OS running the operating system by setting the PL_TRAINER_GPUS when using the Trainer module. A patch is included in the 1.6.0 release.
pytorch-lightning < 1.6.0Upgrade to a patched release:
pytorch-lightning 1.6.0Connected by shared product, vendor, weakness, or advisory.
CVE-2021-4118High· 7.8pytorch-lightning is vulnerable to Deserialization of Untrusted Data
CVE-2026-44484Critical· 9.8Compromise of PyTorch Lightning PyPi Package Versions
CVE-2024-8019Critical· 9.1PyTorch Lightning path traversal vulnerability
CVE-2026-31221High· 7.8PyTorch Lightning load_from_checkpoint has an insecure checkpoint deserialization
CVE-2024-8020High· 7.5PyTorch Lightning denial of service vulnerability