PT-2026-38407 · Pypi · Pytorch-Lightning

·

CVE-2026-44484

·

Published

2026-05-07

·

Updated

2026-09-10

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions PyTorch Lightning versions 2.6.2 through 2.6.3
Description PyTorch Lightning, a deep learning framework used to pretrain and finetune AI models, contains compromised versions that include malicious code. This code introduces functionality consistent with a credential harvesting mechanism, which is designed to collect sensitive information such as passwords or API keys.
Recommendations Pin PyTorch Lightning to version 2.6.1 for versions 2.6.2 through 2.6.3. Immediately rotate all potentially exposed credentials and secrets, including API keys, access tokens, SSH keys, and service account credentials. Rebuild affected systems from a known clean state. Review logs for any suspicious or unauthorized activity.

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-44484
GHSA-W37P-236H-PFX3
PYSEC-2026-3973
PYSEC-2026-508

Affected Products

Pytorch-Lightning