{"id":"PYSEC-2022-43015","details":"In PyTorch before trunk/89695, torch.jit.annotations.parse_type_line can cause arbitrary code execution because eval is used unsafely.","aliases":["BIT-pytorch-2022-45907","CVE-2022-45907","GHSA-47fc-vmwq-366v"],"modified":"2026-06-10T17:51:27.754911892Z","published":"2022-11-26T02:15:00Z","references":[{"type":"FIX","url":"https://github.com/pytorch/pytorch/commit/767f6aa49fe20a2766b9843d01e3b7f7793df6a3"},{"type":"EVIDENCE","url":"https://github.com/pytorch/pytorch/issues/88868"},{"type":"REPORT","url":"https://github.com/pytorch/pytorch/issues/88868"},{"type":"FIX","url":"https://github.com/pytorch/pytorch/issues/88868"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-47fc-vmwq-366v"}],"affected":[{"package":{"name":"torch","ecosystem":"PyPI","purl":"pkg:pypi/torch"},"ranges":[{"type":"GIT","repo":"https://github.com/pytorch/pytorch","events":[{"introduced":"0"},{"fixed":"767f6aa49fe20a2766b9843d01e3b7f7793df6a3"}]},{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.13.1"}]}],"versions":["1.0.0","1.0.1","1.0.1.post2","1.1.0","1.1.0.post2","1.10.0","1.10.1","1.10.2","1.11.0","1.12.0","1.12.1","1.13.0","1.2.0","1.3.0","1.3.0.post2","1.3.1","1.4.0","1.5.0","1.5.1","1.6.0","1.7.0","1.7.1","1.8.0","1.8.1","1.9.0","1.9.1","ciflow/periodic/csl/test87519","ciflow/periodic/csltest88761","ciflow/periodic/csltest88275","ciflow/periodic/317eeb8","ciflow/periodic/2a6d37d","ciflow/periodic/3c32","ciflow/periodic/054a2fd","ciflow/periodic/sha-ec5b83","malfet/tag-2ef5611","malfet/tag-317b1a0","malfet/tag-ec6f767","nightly-binary","v1.8.0-rc1","v1.4.0a0","v1.3.0a0","v1.2.0a0","v1.1.0a0","v1.0rc1","v1.0rc0","v1.0.0a0","v0.1.11","v0.1.10","v0.1.9","v0.1.8","v0.1.7","v0.1.6","v0.1.5","v0.1.4","v0.1.3","v0.1.2","v0.1.1"],"database_specific":{"source":"https://github.com/pypa/advisory-database/blob/main/vulns/torch/PYSEC-2022-43015.yaml"}}],"schema_version":"1.7.5"}