Skip to content
PyTorchGHSA-47fc-vmwq-366v

PyTorch vulnerable to arbitrary code execution

Critical9.8CVE-2022-45907 · Published Nov 26, 2022 · updated Nov 13, 2024

GitHub advisory

Affected versions

PackageAffectedFixed in
torch
PyPI
< 1.13.11.13.1
Details and references

In PyTorch before trunk/89695, torch.jit.annotations.parse_type_line can cause arbitrary code execution because eval is used unsafely. The fix for this issue is available in version 1.13.1. There is a release checker in [issue #89855](https://github.com/pytorch/pytorch/issues/89855).

CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Severity from
GitHub (reviewed advisory)
Weakness
CWE-77
Also known as
BIT-pytorch-2022-45907, CVE-2022-45907, PYSEC-2022-43015

More PyTorch advisories

All PyTorch

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.