Vulnerabilities > Lightningai

DATE CVE VULNERABILITY TITLE RISK
2024-06-06 CVE-2024-5452 Improper Control of Dynamically-Managed Code Resources vulnerability in Lightningai Pytorch Lightning
A remote code execution (RCE) vulnerability exists in the lightning-ai/pytorch-lightning library version 2.2.1 due to improper handling of deserialized user input and mismanagement of dunder attributes by the `deepdiff` library.
network
low complexity
lightningai CWE-913
critical
9.8
2022-03-05 CVE-2022-0845 Code Injection vulnerability in Lightningai Pytorch Lightning
Code Injection in GitHub repository pytorchlightning/pytorch-lightning prior to 1.6.0.
network
low complexity
lightningai CWE-94
critical
9.8
2021-12-23 CVE-2021-4118 Deserialization of Untrusted Data vulnerability in Lightningai Pytorch Lightning
pytorch-lightning is vulnerable to Deserialization of Untrusted Data
local
low complexity
lightningai CWE-502
7.8