PT-2026-94063 · Lightgbm Org+1 · Lightgbm
CVSS v4.0
8.5
High
| Vector | AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
LightGBM versions prior to 4.7.1
Description
Failure to validate child and split array values when parsing text models allows for out-of-bounds memory writes during SHAP (SHapley Additive exPlanations, a method used to explain the output of machine learning models) prediction. An attacker can create malicious model files containing invalid node references to trigger these writes at specific offsets within the
leaf depth buffer during the computation of feature contributions.Recommendations
Update LightGBM to version 4.7.1 or later.
Exploit
Fix
Memory Corruption
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Lightgbm