Junglewise Threat Intelligence

CVE-2024-5980: PYSEC-2026-3975 - pytorch-lightning vulnerable to Arbitrary File Write via /v1/runs API endpoint

CVE-2024-5980 · Severity: low · CVSS 3 · Published 2026-09-10

Technologies: lightning (PyPI), pytorch-lightning (PyPI). Vendors: PyPI.

Executive brief

pytorch-lightning vulnerable to Arbitrary File Write via /v1/runs API endpoint

Affected products

  • PyPI lightning
  • PyPI pytorch-lightning

Related threats