PyTorch Vulnerable to Remote Code Execution via Untrusted Checkpoint Files
GHSA-63cw-57p8-fm3p · BIT-pytorch-2026-24747 · CVE-2026-24747 · PYSEC-2026-1856 · PYSEC-2026-2286
Published · Modified
AI SAST
Find this class of vulnerability in your own code
Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.
Description
Summary
A vulnerability in PyTorch's weights_only unpickler allows an attacker to craft a malicious checkpoint file (.pth) that, when loaded with torch.load(..., weights_only=True), can corrupt memory and potentially lead to arbitrary code execution.
Vulnerability Details
The weights_only=True unpickler failed to properly validate pickle opcodes and storage metadata, allowing:
- Heap memory corruption via
SETITEM/SETITEMSopcodes applied to non-dictionary types - Storage size mismatch between declared element count and actual data in the archive
Impact
An attacker who can convince a user to load a malicious checkpoint file may achieve arbitrary code execution in the context of the victim's process.
Credit
Ji'an Zhou
References
- WEB https://github.com/pytorch/pytorch/security/advisories/GHSA-63cw-57p8-fm3p
- ADVISORY https://nvd.nist.gov/vuln/detail/CVE-2026-24747
- WEB https://github.com/pytorch/pytorch/issues/163105
- PACKAGE https://github.com/pytorch/pytorch
- WEB https://github.com/pytorch/pytorch/163122/commit/954dc5183ee9205cbe79876ad05dd2d9ae752139
- WEB https://github.com/pytorch/pytorch/releases/tag/v2.10.0
Ready to move
Start Securing
Free, no credit card | First findings in minutes