CRITICAL🇵🇱 Wersja polska

CVE-2026-44484

CVSS 9.3v4.0pub. 2026-05-14upd. 2026-06-30

PyTorch Lightning is a deep learning framework to pretrain and finetune AI models. Versions 2.6.2 and 2.6.2 have introduced functionality consistent with a credential harvesting mechanism.

🤖 AI Analysis
How it works

According to the description, version 2.6.2 of the PyTorch Lightning library introduces code whose behavior is consistent with a credential harvesting mechanism – i.e., unauthorized interception of user or environment credentials. CWE-506 indicates embedded malicious code in a software package. An attacker or compromised supply chain could have introduced such functionality directly into the library distribution.

Impact

An attacker can gain access to credentials (e.g., API keys, tokens, passwords) stored in the environment where the library is running, which can lead to account takeover, data leakage, and further compromise of infrastructure.

Mitigation & patch

Immediately remove PyTorch Lightning version 2.6.2 from all environments and do not install this version. Apply patches available from the vendor in accordance with the references (GitHub Security Advisory GHSA-w37p-236h-pfx3). It is also recommended to audit environments where version 2.6.2 was installed for potential credential leakage.

Who is affected

PyTorch Lightning version 2.6.2

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • Lightningai Pytorch Lightning

    APP
    Lightningai
    2.6.22.6.3
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2024-8019CRITICAL9.1PL ✓same product

RCE przez upload pliku w PyTorch Lightning (Windows) – CVE-2024-8019

CVE-2024-5980CRITICAL9.8PL ✓same product

Path Traversal w PyTorch Lightning umożliwiający RCE przez złośliwy plugin

CVE-2024-5452CRITICAL9.8PL ✓same product

RCE w pytorch-lightning przez podatną deserializację obiektów deepdiff

CVE-2022-0845CRITICAL9.8PL ✓same product

Code Injection w PyTorch Lightning przed wersją 1.6.0

CVE-2026-58659HIGH8.4PL ✓same product

RCE w PyTorch Lightning — wykonanie kodu z pliku checkpoint