CRITICAL 9.8 PyPI

PyTorch vulnerable to arbitrary code execution

GHSA-47fc-vmwq-366v · BIT-pytorch-2022-45907 · CVE-2022-45907 · PYSEC-2022-43015

Published · Modified

AI SAST

Find this class of vulnerability in your own code

Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.

Description

In PyTorch before trunk/89695, torch.jit.annotations.parse_type_line can cause arbitrary code execution because eval is used unsafely. The fix for this issue is available in version 1.13.1. There is a release checker in issue #89855.

Ready to move

Start Securing

Free, no credit card | First findings in minutes