Junglewise Threat Intelligence

CVE-2026-31221: Lightning AI PyTorch Lightning insecure deserialization in checkpoint loading

CVE-2026-31221 · Severity: high · CVSS 7.8 · Published 2026-05-12

Technologies: Lightning-AI Pytorch-Lightning, lightning (PyPI). Vendors: PyPI.

Executive brief

PyTorch Lightning, a popular framework for training AI models, contains a security flaw in how it loads saved model checkpoints. If a user is tricked into loading a maliciously crafted checkpoint file, an attacker can execute arbitrary commands on the user's computer. This could lead to full system compromise, data theft, or unauthorized access to research environments.

Technical details

An insecure deserialization vulnerability (CWE-502) exists in PyTorch Lightning versions <= 2.6.0 within the checkpoint loading mechanism. The 'LightningModule.load_from_checkpoint()' method internally calls 'torch.load()' without enabling the 'weights_only=True' security restriction. This allows the Pickle module to deserialize arbitrary Python objects. An attacker can exploit this by providing a crafted checkpoint file; when a user loads this file, it triggers arbitrary code execution. The attack requires the victim to load the malicious file (User Interaction), typically in a local environment.

Affected products

  • Lightning-AI pytorch-lightning <= 2.6.0

Timeline

  • 2026-05-12: disclosed
  • 2026-05-12: advisory: NVD publication date
  • 2026-05-18: other: GitHub Advisory reviewed

References

Related threats