Lightning AI's vulnerability profile centers on PyTorch Lightning, a machine-learning framework that sits in the development and deployment stack of deep-learning applications, and its exposure skews strongly toward critical-severity outcomes. The recurring weakness classes—including untrusted deserialization, embedded malicious code, code injection, and path traversal—reflect the framework's role as a dynamic code execution environment where input validation and resource isolation are essential to prevent model-poisoning and supply-chain attacks. Defenders should treat this vendor's security advisories as high-priority for any workload that ingests external models or training data; current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Lightningai over time
Signals from CVEs in this vendor scope (9 CVEs).
9 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-5452CRITICAL A remote code execution (RCE) vulnerability exists in the lightning-ai/pytorch-lightning library version 2.2.1 due to improper handling of deserialized user input and mismanagement | Jun 6, 2024 | 9.8 | 44 | NO | NO |
CVE-2026-44484CRITICAL PyTorch Lightning is a deep learning framework to pretrain and finetune AI models. Versions 2.6.2 and 2.6.2 have introduced functionality consistent with a credential harvesting me | May 14, 2026 | 9.8 | 37 | NO | NO |
CVE-2026-58659HIGH PyTorch Lightning through 2.6.5, fixed in commit d710d68, contains a remote code execution vulnerability in the _load_state function that imports and executes attacker-controlled m | Jul 15, 2026 | 7.8 | 33 | NO | NO |
CVE-2024-5980CRITICAL A vulnerability in the /v1/runs API endpoint of lightning-ai/pytorch-lightning v2.2.4 allows attackers to exploit path traversal when extracting tar.gz files. When the LightningApp | Jun 27, 2024 | 9.8 | 30 | NO | NO |
CVE-2026-31221HIGH PyTorch-Lightning versions 2.6.0 and earlier contain an insecure deserialization vulnerability (CWE-502) in the checkpoint loading mechanism. The LightningModule.load_from_checkpoi | May 12, 2026 | 7.8 | 27 | NO | NO |
CVE-2021-4118HIGH pytorch-lightning is vulnerable to Deserialization of Untrusted Data | Dec 23, 2021 | 7.8 | 26 | NO | NO |
CVE-2024-8019CRITICAL In lightning-ai/pytorch-lightning version 2.3.2, a vulnerability exists in the `LightningApp` when running on a Windows host. The vulnerability occurs at the `/api/v1/upload_file/` | Mar 20, 2025 | 9.1 | 24 | NO | NO |
CVE-2022-0845CRITICAL Code Injection in GitHub repository pytorchlightning/pytorch-lightning prior to 1.6.0. | Mar 5, 2022 | 9.8 | 24 | NO | NO |
CVE-2024-8020HIGH A vulnerability in lightning-ai/pytorch-lightning version 2.3.2 allows an attacker to cause a denial of service by sending an unexpected POST request to the `/api/v1/state` endpoin | Mar 20, 2025 | 7.5 | 20 | NO | NO |
Signals from CVEs in this vendor scope (9 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Lightningai.
Media articles that mention a CVE ID that affects a product developed by Lightningai — matched by CVE ID, not by vendor name.