← Vulnerability feed

Vulnerability record · CVE-2024-5452 · published 6 June 2024

CVE-2024-5452: Lightningai pytorch lightning mass assignment vulnerability

Lightningai · Pytorch Lightning

A remote code execution (RCE) vulnerability exists in the lightning-ai/pytorch-lightning library version 2.2.1 due to improper handling of deserialized user input and mismanagement of dunder attributes by the `deepdiff` library. The library uses `deepdiff.Delta` objects to modify application state based on frontend actions. However, it is possible to bypass the intended restrictions on modifying dunder attributes, allowing an attacker to construct a serialized delta that passes the deserializer whitelist and contains dunder attributes. When processed, this can be exploited to access other modules, classes, and instances, leading to arbitrary attribute write and total RCE on any self-hosted pytorch-lightning application in its default configuration, as the delta endpoint is enabled by default.

9.8 CVSS 3.1 Critical EPSS 27% · top 2.0% CWE-915 · Mass assignmentCWE-913 · Improper control of dynamically-managed code
9.8CVSS 3.1 base score
27%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
3References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

A remote code execution (RCE) vulnerability exists in the lightning-ai/pytorch-lightning library version 2.2.1 due to improper handling of deserialized user input and mismanagement of dunder attributes by the `deepdiff` library. The library uses `deepdiff.Delta` objects to modify application state based on frontend actions. However, it is possible to bypass the intended restrictions on modifying dunder attributes, allowing an attacker to construct a serialized delta that passes the deserializer whitelist and contains dunder attributes. When processed, this can be exploited to access other modules, classes, and instances, leading to arbitrary attribute write and total RCE on any self-hosted pytorch-lightning application in its default configuration, as the delta endpoint is enabled by default.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2024-5452 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2024-5980Lightningai pytorch lightning path traversal vulnerabilityA vulnerability in the /v1/runs API endpoint of lightning-ai/pytorch-lightning v2.2.4 allows attackers to exploit path traversal when extracting tar.…EPSS 1.3%9.8CVE-2022-0845Lightningai pytorch lightning code injection vulnerabilityCode Injection in GitHub repository pytorchlightning/pytorch-lightning prior to 1.6.0.EPSS 1.00%9.3CVE-2026-44484Lightningai pytorch lightning inclusion from untrusted sphere vulnerabilityPyTorch Lightning is a deep learning framework to pretrain and finetune AI models. Versions 2.6.2 and 2.6.2 have introduced functionality consistent …EPSS 0.67%9.1CVE-2024-8019Lightningai pytorch lightning unrestricted file upload vulnerabilityIn lightning-ai/pytorch-lightning version 2.3.2, a vulnerability exists in the `LightningApp` when running on a Windows host. The vulnerability occur…EPSS 1.1%8.4CVE-2026-58659Lightningai pytorch lightning vulnerabilityPyTorch Lightning through 2.6.5, fixed in commit d710d68, contains a remote code execution vulnerability in the _load_state function that imports and…EPSS 0.63%7.8CVE-2026-31221Lightningai pytorch lightning deserialization of untrusted data vulnerabilityPyTorch-Lightning versions 2.6.0 and earlier contain an insecure deserialization vulnerability (CWE-502) in the checkpoint loading mechanism. The Lig…EPSS 0.55%7.8CVE-2021-4118Lightningai pytorch lightning deserialization of untrusted data vulnerabilitypytorch-lightning is vulnerable to Deserialization of Untrusted DataEPSS 0.98%7.5CVE-2024-8020Lightningai pytorch lightning vulnerabilityA vulnerability in lightning-ai/pytorch-lightning version 2.3.2 allows an attacker to cause a denial of service by sending an unexpected POST request…EPSS 0.63%

Source: NIST National Vulnerability Database (record CVE-2024-5452), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.