CRITICAL 9.8 PyPI

Code Injection in PyTorch Lightning

GHSA-r5qj-cvf9-p85h · CVE-2022-0845 · PYSEC-2022-181

Published · Modified

Description

PyTorch Lightning version 1.5.10 and prior is vulnerable to code injection. An attacker could execute commands on the target OS running the operating system by setting the PL_TRAINER_GPUS when using the Trainer module. A patch is included in the 1.6.0 release.

Ready to move

Start Securing

Free, no credit card | First findings in minutes