pytorch-lightningGHSA-4cv3-v7pv-rfhf
PyTorch Lightning path traversal vulnerability
Critical9.1CVE-2024-8019 · Published Mar 20, 2025 · updated Sep 10, 2026
In lightning-ai/pytorch-lightning version 2.3.2, a vulnerability exists in the `LightningApp` when running on a Windows host. The vulnerability occurs at the `/api/v1/upload_file/` endpoint, allowing an attacker to write or overwrite arbitrary files by providing a crafted filename. This can lead to potential remote code execution (RCE) by overwriting critical files or placing malicious files in sensitive locations.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| pytorch-lightning PyPI | < 2.4.0 | 2.4.0 |
Details and references
- CVSS 3.0
- CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-434
- Also known as
- CVE-2024-8019, PYSEC-2026-3970, PYSEC-2026-507
More pytorch-lightning advisories
All pytorch-lightning| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Sep 10 | pytorch-lightning vulnerable to Arbitrary File Write via /v1/runs API endpoint | Critical9.1 | 2.3.3 |
| Sep 10 | Remote code execution in pytorch lightning | Critical9.8 | 2.3.3 |
| Jul 15 | pytorch-lightning: remote code execution | High7.8 | 2.6.6 |
| May 12 | PyTorch Lightning load_from_checkpoint has an insecure checkpoint deserialization | High7.8 | No fix yet |
| May 7 | Compromise of PyTorch Lightning PyPi Package Versions | Critical9.8 | No fix yet |
| Mar 202025 | PyTorch Lightning denial of service vulnerability | High7.5 | No fix yet |