CVE-2024-8019Critical· 9.1▾ MidnightPyTorch Lightning path traversal vulnerability
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 50.1 · likelihood 0.2 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Sep 12.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
1.1%
1.1% → 1.1%
In lightning-ai/pytorch-lightning version 2.3.2, a vulnerability exists in the LightningApp when running on a Windows host. The vulnerability occurs at the /api/v1/upload_file/ endpoint, allowing an attacker to write or overwrite arbitrary files by providing a crafted filename. This can lead to potential remote code execution (RCE) by overwriting critical files or placing malicious files in sensitive locations.
pytorch-lightning < 2.4.0Upgrade to a patched release:
pytorch-lightning 2.4.0Connected by shared product, vendor, weakness, or advisory.
CVE-2026-44484Critical· 9.8Compromise of PyTorch Lightning PyPi Package Versions
CVE-2026-31221High· 7.8PyTorch Lightning load_from_checkpoint has an insecure checkpoint deserialization
CVE-2024-8020High· 7.5PyTorch Lightning denial of service vulnerability
CVE-2022-0845Critical· 9.8Code Injection in PyTorch Lightning
CVE-2021-4118High· 7.8pytorch-lightning is vulnerable to Deserialization of Untrusted Data