PT-2024-37290 · Pypi · Pytorch-Lightning

CVE-2024-5980

·

Published

2024-06-27

·

Updated

2026-09-10

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: pytorch-lightning version 2.2.4
Description: A path traversal issue exists in the "/v1/runs" API endpoint, allowing attackers to exploit this vulnerability when extracting tar.gz files. This can be used to deploy malicious tar.gz plugins that embed arbitrary files, potentially leading to arbitrary files being written to any directory in the victim's local file system and remote code execution.
Recommendations: For pytorch-lightning version 2.2.4, as a temporary workaround, consider disabling the plugin server to minimize the risk of exploitation. Avoid using the /v1/runs API endpoint until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

RCE

Unrestricted File Upload

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-5980
GHSA-MR7H-W2QC-FFC2
PYSEC-2026-386
PYSEC-2026-3975

Affected Products

Pytorch-Lightning