PyTorch Lightning is a deep learning framework to pretrain and finetune AI models. Versions 2.6.2 and 2.6.2 have introduced functionality consistent with a credential harvesting mechanism.
According to the description, version 2.6.2 of the PyTorch Lightning library introduces code whose behavior is consistent with a credential harvesting mechanism – i.e., unauthorized interception of user or environment credentials. CWE-506 indicates embedded malicious code in a software package. An attacker or compromised supply chain could have introduced such functionality directly into the library distribution.
An attacker can gain access to credentials (e.g., API keys, tokens, passwords) stored in the environment where the library is running, which can lead to account takeover, data leakage, and further compromise of infrastructure.
Immediately remove PyTorch Lightning version 2.6.2 from all environments and do not install this version. Apply patches available from the vendor in accordance with the references (GitHub Security Advisory GHSA-w37p-236h-pfx3). It is also recommended to audit environments where version 2.6.2 was installed for potential credential leakage.
PyTorch Lightning version 2.6.2
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XLightningai Pytorch Lightning
APPLightningai2.6.22.6.3
Related vulnerabilities
RCE przez upload pliku w PyTorch Lightning (Windows) – CVE-2024-8019
Path Traversal w PyTorch Lightning umożliwiający RCE przez złośliwy plugin
RCE w pytorch-lightning przez podatną deserializację obiektów deepdiff
Code Injection w PyTorch Lightning przed wersją 1.6.0
RCE w PyTorch Lightning — wykonanie kodu z pliku checkpoint