In lightning-ai/pytorch-lightning version 2.3.2, a vulnerability exists in the `LightningApp` when running on a Windows host. The vulnerability occurs at the `/api/v1/upload_file/` endpoint, allowing an attacker to write or overwrite arbitrary files by providing a crafted filename. This can lead to potential remote code execution (RCE) by overwriting critical files or placing malicious files in sensitive locations.
The vulnerability (CWE-434 – Unrestricted Upload of File with Dangerous Type) occurs in the `/api/v1/upload_file/` endpoint. An attacker sends an HTTP request containing a crafted filename that is not properly validated or sanitized. This makes it possible to write or overwrite any file in the host file system – including files critical to the system or application operation. Placing a malicious file in an appropriate location can result in execution of arbitrary code on the server.
An attacker can overwrite critical system or application files or place malicious files in sensitive locations, which may lead to remote code execution (RCE) and compromise the integrity and availability of the system.
Security patches provided by the vendor should be applied according to the references — the fix is available in the GitHub repository at: https://github.com/lightning-ai/pytorch-lightning/commit/330af381de88cff17515418a341cbc1f9f127f9a
lightning-ai/pytorch-lightning version 2.3.2, running as LightningApp on a Windows host
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:HLightningai Pytorch Lightning
APPLightningai2.3.2
Related vulnerabilities
PyTorch Lightning – mechanizm harvesting poświadczeń (Embedded Malicious Code)
Path Traversal w PyTorch Lightning umożliwiający RCE przez złośliwy plugin
RCE w pytorch-lightning przez podatną deserializację obiektów deepdiff
Code Injection w PyTorch Lightning przed wersją 1.6.0
RCE w PyTorch Lightning — wykonanie kodu z pliku checkpoint