CRITICAL🇵🇱 Wersja polska

CVE-2024-8019

CVSS 9.1v3.1pub. 2025-03-20upd. 2025-08-01

In lightning-ai/pytorch-lightning version 2.3.2, a vulnerability exists in the `LightningApp` when running on a Windows host. The vulnerability occurs at the `/api/v1/upload_file/` endpoint, allowing an attacker to write or overwrite arbitrary files by providing a crafted filename. This can lead to potential remote code execution (RCE) by overwriting critical files or placing malicious files in sensitive locations.

🤖 AI Analysis
How it works

The vulnerability (CWE-434 – Unrestricted Upload of File with Dangerous Type) occurs in the `/api/v1/upload_file/` endpoint. An attacker sends an HTTP request containing a crafted filename that is not properly validated or sanitized. This makes it possible to write or overwrite any file in the host file system – including files critical to the system or application operation. Placing a malicious file in an appropriate location can result in execution of arbitrary code on the server.

Impact

An attacker can overwrite critical system or application files or place malicious files in sensitive locations, which may lead to remote code execution (RCE) and compromise the integrity and availability of the system.

Mitigation & patch

Security patches provided by the vendor should be applied according to the references — the fix is available in the GitHub repository at: https://github.com/lightning-ai/pytorch-lightning/commit/330af381de88cff17515418a341cbc1f9f127f9a

Who is affected

lightning-ai/pytorch-lightning version 2.3.2, running as LightningApp on a Windows host

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
  • Lightningai Pytorch Lightning

    APP
    Lightningai
    2.3.2
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
RCE
CWE
References

Related vulnerabilities

CVE-2026-44484CRITICAL9.3PL ✓same product

PyTorch Lightning – mechanizm harvesting poświadczeń (Embedded Malicious Code)

CVE-2024-5980CRITICAL9.8PL ✓same product

Path Traversal w PyTorch Lightning umożliwiający RCE przez złośliwy plugin

CVE-2024-5452CRITICAL9.8PL ✓same product

RCE w pytorch-lightning przez podatną deserializację obiektów deepdiff

CVE-2022-0845CRITICAL9.8PL ✓same product

Code Injection w PyTorch Lightning przed wersją 1.6.0

CVE-2026-58659HIGH8.4PL ✓same product

RCE w PyTorch Lightning — wykonanie kodu z pliku checkpoint