pytorch-lightning@2.6.6

PyTorch Lightning is the lightweight PyTorch wrapper for ML researchers. Scale your models. Write less boilerplate.

Direct Vulnerabilities

Known vulnerabilities in the pytorch-lightning package. This does not include vulnerabilities belonging to this package’s dependencies.

Fix vulnerabilities automatically

Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.

Fix for free
VulnerabilityVulnerable Version
  • H
Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection')

pytorch-lightning is a lightweight PyTorch wrapper for ML researchers. Scale your models. Write less boilerplate.

Affected versions of this package are vulnerable to Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') via the _load_state function that imports and executes module names specified in checkpoint _instantiator hyperparameters. An attacker can achieve arbitrary code execution by providing a malicious checkpoint file that is loaded through the load_from_checkpoint function.

How to fix Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection')?

A fix was pushed into the master branch but not yet published.

[0,)