CVE-2026-4538 identifies a deserialization vulnerability in PyTorch version 2.10.0, specifically affecting an unknown function within the pt2 Loading Handler component. Rated as Medium severity (CVSS 5.3), this flaw requires local access and low privileges, with a low impact on confidentiality, integrity, and availability. While an exploit is publicly available, there is currently no evidence of active exploitation, and the vendor has not yet released a patch despite early notification.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2.10.0CPE matchmatch criteria | cpe:2.3:a:linuxfoundation:pytorch:2.10.0:*:*:*:*:python:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.