Skip to content
pytorch-lightningGHSA-4cv3-v7pv-rfhf

PyTorch Lightning path traversal vulnerability

Critical9.1CVE-2024-8019 · Published Mar 20, 2025 · updated Sep 10, 2026

In lightning-ai/pytorch-lightning version 2.3.2, a vulnerability exists in the `LightningApp` when running on a Windows host. The vulnerability occurs at the `/api/v1/upload_file/` endpoint, allowing an attacker to write or overwrite arbitrary files by providing a crafted filename. This can lead to potential remote code execution (RCE) by overwriting critical files or placing malicious files in sensitive locations.

GitHub advisory

Affected versions

PackageAffectedFixed in
pytorch-lightning
PyPI
< 2.4.02.4.0
Details and references
CVSS 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
Severity from
GitHub (reviewed advisory)
Weakness
CWE-434
Also known as
CVE-2024-8019, PYSEC-2026-3970, PYSEC-2026-507

More pytorch-lightning advisories

All pytorch-lightning
Advisory
pytorch-lightning vulnerable to Arbitrary File Write via /v1/runs API endpoint
Critical9.1Sep 10
Remote code execution in pytorch lightning
Critical9.8Sep 10
pytorch-lightning: remote code execution
High7.8Jul 15
PyTorch Lightning load_from_checkpoint has an insecure checkpoint deserialization
High7.8May 12
Compromise of PyTorch Lightning PyPi Package Versions
Critical9.8May 7
PyTorch Lightning denial of service vulnerability
High7.5Mar 20, 2025

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.