Junglewise Threat Intelligence

CVE-2021-4118: PYSEC-2026-3968 - pytorch-lightning is vulnerable to Deserialization of Untrusted Data

CVE-2021-4118 · Severity: low · CVSS 3.1 · Published 2026-09-10

Technologies: lightning (PyPI), pytorch-lightning (PyPI). Vendors: PyPI.

Executive brief

PyTorch Lightning is a popular machine learning framework used to simplify deep learning model training. The framework deserializes untrusted data without proper validation, allowing an attacker to execute arbitrary code when loading a malicious checkpoint file. This could lead to complete compromise of the training environment and access to sensitive model data.

Technical details

PyTorch Lightning is vulnerable to unsafe deserialization of untrusted data (CWE-502). The vulnerability exists in checkpoint loading functionality, where the framework uses Python's pickle deserialization on user-supplied model checkpoint files without sufficient validation. An attacker can craft a malicious checkpoint file that executes arbitrary Python code during the unpickling process. The attack requires local file system access or the ability to trick a user into loading a malicious checkpoint; no network access or authentication is required. Exploitation results in arbitrary code execution with the privileges of the user running the training process. The vulnerability was fixed in version 1.6.0.

Affected products

  • PyTorch Lightning Lightning before 1.6.0

Timeline

  • 2021-12-23: disclosed
  • 2022-01-06: advisory
  • 2022-01-06: patched: Version 1.6.0 released

References

Related threats