Skip to content
pytorch-lightningGHSA-r5qj-cvf9-p85h

Code Injection in PyTorch Lightning

Critical9.8CVE-2022-0845 · Published Mar 6, 2022 · updated Sep 10, 2026

GitHub advisory

Affected versions

PackageAffectedFixed in
pytorch-lightning
PyPI
< 1.6.01.6.0
Details and references

PyTorch Lightning version 1.5.10 and prior is vulnerable to code injection. An attacker could execute commands on the target OS running the operating system by setting the `PL_TRAINER_GPUS` when using the `Trainer` module. A [patch](https://github.com/pytorchlightning/pytorch-lightning/commit/8b7a12c52e52a06408e9231647839ddb4665e8ae) is included in the `1.6.0` release.

CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Severity from
GitHub (reviewed advisory)
Weakness
CWE-94
Also known as
CVE-2022-0845, PYSEC-2022-181, PYSEC-2026-3969

More pytorch-lightning advisories

All

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.