Skip to content
pytorch-lightningPYSEC-2026-3967

PyTorch Lightning through 2.6.5, fixed in commit d710d68, contains a remote code execution vulnerability in the _load_state function that imports and executes attacker-controlled module names from checkpoint _instantiator hyperparameters. Attackers can craft malicious checkpoint files that bypass we

High7.8CVE-2026-58659 · Published Jul 15, 2026 · updated Sep 10, 2026

Source advisory

Affected versions

PackageAffectedFixed in
pytorch-lightning
PyPI
< 2.6.62.6.6

Changes since it was listed

DateChange
Sep 25Severity: Unrated to High
Details and references

PyTorch Lightning through 2.6.5, fixed in commit d710d68, contains a remote code execution vulnerability in the _load_state function that imports and executes attacker-controlled module names from checkpoint _instantiator hyperparameters. Attackers can craft malicious checkpoint files that bypass weights_only=True protections to execute arbitrary code when LightningModule.load_from_checkpoint is called.

CVSS 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Severity from
NVD
Also known as
CVE-2026-58659, GHSA-qqmf-gpg7-g8gw, PYSEC-2026-3624

More pytorch-lightning advisories

All
DateAdvisory
Sep 10Remote code execution in pytorch lightning
CVE-2024-5452Critical9.8fixed in 2.3.3
Sep 10pytorch-lightning vulnerable to Arbitrary File Write via /v1/runs API endpoint
CVE-2024-5980Critical9.1fixed in 2.3.3
May 12PyTorch Lightning load_from_checkpoint has an insecure checkpoint deserialization
CVE-2026-31221High7.8no fix yet
May 7Compromise of PyTorch Lightning PyPi Package Versions
CVE-2026-44484Critical9.8no fix yet
Mar 202025PyTorch Lightning denial of service vulnerability
CVE-2024-8020High7.5no fix yet
Mar 202025PyTorch Lightning path traversal vulnerability
CVE-2024-8019Critical9.1fixed in 2.4.0

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.