PyPi: Lightning

CVE-2024-5980

Safety vulnerability ID: 72092

This vulnerability was reviewed by experts

The information on this page was manually curated by our Cybersecurity Intelligence Team.

Created at Jun 27, 2024 Updated at Dec 15, 2024
Scan your Python projects for vulnerabilities →

Advisory

A vulnerability in the /v1/runs API endpoint of lightning-ai/pytorch-lightning affected versions allows attackers to exploit path traversal when extracting tar.gz files. When LightningApp is running with the plugin_server, attackers can deploy malicious tar.gz plugins that embed arbitrary files with path traversal vulnerabilities. This can result in arbitrary files being written to any directory in the victim's local file system, potentially leading to remote code execution.

Affected package

lightning

Latest version: 2.4.0

The Deep Learning framework to train, deploy, and ship AI products Lightning fast.

Affected versions

Fixed versions

Vulnerability changelog

This vulnerability has no description

Resources

Use this package?

Scan your Python project for dependency vulnerabilities in two minutes

Scan your application