{"id":"PYSEC-2026-3624","details":"PyTorch Lightning through 2.6.5, fixed in commit d710d68, contains a remote code execution vulnerability in the _load_state function that imports and executes attacker-controlled module names from checkpoint _instantiator hyperparameters. Attackers can craft malicious checkpoint files that bypass weights_only=True protections to execute arbitrary code when LightningModule.load_from_checkpoint is called.","aliases":["CVE-2026-58659","GHSA-qqmf-gpg7-g8gw","PYSEC-2026-3967"],"modified":"2026-09-10T13:10:44.573169284Z","published":"2026-07-15T18:16:48.743Z","references":[{"type":"REPORT","url":"https://github.com/Lightning-AI/pytorch-lightning/issues/21822"},{"type":"FIX","url":"https://github.com/Lightning-AI/pytorch-lightning/commit/d710d689510d50e800f53b3cd773cbca20b1f86f"},{"type":"FIX","url":"https://github.com/Lightning-AI/pytorch-lightning/pull/21832"},{"type":"FIX","url":"https://www.vulncheck.com/advisories/pytorch-lightning-arbitrary-code-execution-via-instantiator-hyperparameter"},{"type":"WEB","url":"https://github.com/Lightning-AI/pytorch-lightning/releases/tag/2.6.6"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-qqmf-gpg7-g8gw"}],"affected":[{"package":{"name":"lightning","ecosystem":"PyPI","purl":"pkg:pypi/lightning"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.6.6"}]}],"versions":["1.8.0","1.8.0.post1","1.8.0rc1","1.8.0rc2","1.8.1","1.8.2","1.8.3","1.8.3.post0","1.8.3.post1","1.8.3.post2","1.8.4","1.8.4.post0","1.8.5","1.8.5.post0","1.8.6","1.9.0","1.9.0rc0","1.9.1","1.9.2","1.9.3","1.9.4","1.9.5","2.0.0","2.0.0rc0","2.0.1","2.0.1.post0","2.0.2","2.0.3","2.0.4","2.0.5","2.0.6","2.0.7","2.0.8","2.0.9","2.0.9.post0","2.1.0","2.1.0rc0","2.1.0rc1","2.1.1","2.1.2","2.1.3","2.1.4","2.2.0","2.2.0.post0","2.2.0rc0","2.2.1","2.2.2","2.2.3","2.2.4","2.2.5","2.3.0","2.3.0.dev20240318","2.3.0.dev20240324","2.3.0.dev20240328","2.3.0.dev20240331","2.3.0.dev20240407","2.3.0.dev20240414","2.3.0.dev20240421","2.3.0.dev20240428","2.3.0.dev20240505","2.3.0.dev20240519","2.3.0.dev20240526","2.3.0.dev20240602","2.3.0.dev20240609","2.3.0.dev20240616","2.3.0.dev20240623","2.3.1","2.3.2","2.3.3","2.4.0","2.4.0.dev20240630","2.4.0.dev20240707","2.4.0.dev20240714","2.4.0.dev20240721","2.4.0.dev20240728","2.4.0.dev20240804","2.4.0.dev20240811","2.4.0.dev20240818","2.4.0.dev20240825","2.4.0.dev20240901","2.4.0.dev20240908","2.4.0.dev20240915","2.4.0.dev20240922","2.4.0.dev20240929","2.4.0.dev20241006","2.4.0.dev20241013","2.4.0.dev20241020","2.5.0","2.5.0.dev20241027","2.5.0.dev20241103","2.5.0.dev20241110","2.5.0.dev20241117","2.5.0.dev20241124","2.5.0.dev20241201","2.5.0.dev20241208","2.5.0.dev20241215","2.5.0.dev20241222","2.5.0.dev20241229","2.5.0.dev20250105","2.5.0.dev20250112","2.5.0.dev20250119","2.5.0.dev20250126","2.5.0.dev20250202","2.5.0.dev20250209","2.5.0.dev20250216","2.5.0.dev20250223","2.5.0.dev20250302","2.5.0.dev20250309","2.5.0.dev20250316","2.5.0.post0","2.5.0rc0","2.5.1","2.5.1.dev20250323","2.5.1.dev20250330","2.5.1.dev20250406","2.5.1.dev20250413","2.5.1.dev20250420","2.5.1.dev20250427","2.5.1.dev20250504","2.5.1.dev20250511","2.5.1.dev20250518","2.5.1.dev20250525","2.5.1.dev20250601","2.5.1.dev20250608","2.5.1.dev20250615","2.5.1.dev20250622","2.5.1.post0","2.5.1rc0","2.5.1rc1","2.5.1rc2","2.5.2","2.5.3","2.5.4","2.5.5","2.5.6","2.6.0","2.6.0.dev0","2.6.0.dev20250629","2.6.0.dev20250706","2.6.0.dev20250713","2.6.0.dev20250720","2.6.0.dev20250727","2.6.0.dev20250803","2.6.0.dev20250810","2.6.0.dev20250817","2.6.0.dev20250824","2.6.0.dev20250831","2.6.0.dev20250914","2.6.0.dev20250921","2.6.0.dev20250928","2.6.0.dev20251005","2.6.0.dev20251012","2.6.0.dev20251019","2.6.0.dev20251026","2.6.0.dev20251102","2.6.0.dev20251109","2.6.0.dev20251116","2.6.0.dev20251123","2.6.0.dev20251130","2.6.0.dev20251207","2.6.0.dev20251214","2.6.0.dev20251221","2.6.0.dev20251228","2.6.0.dev20260104","2.6.0.dev20260111","2.6.0.dev20260118","2.6.0.dev20260125","2.6.1","2.6.1.dev20260201","2.6.4","2.6.5"],"ecosystem_specific":{},"database_specific":{"source":"https://github.com/pypa/advisory-database/blob/main/vulns/lightning/PYSEC-2026-3624.yaml"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"}]}