Description
PyTorch Lightning is a deep learning framework to pretrain and finetune AI models. Versions 2.6.2 and 2.6.2 have introduced functionality consistent with a credential harvesting mechanism.
Published: 2026-05-14
Score: 9.3 Critical
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

PyTorch Lightning 2.6.2 introduced code that can capture and transmit user credentials, effectively enabling credential harvesting. This weakness corresponds to CWE‑506. An attacker who can influence the installation of the compromised package or execute its code can obtain stored credentials, potentially compromising other services or data.

Affected Systems

The vulnerable product is PyTorch Lightning 2.6.2, released by Lightning‑AI. Any system that installs or imports this version from PyPI is at risk.

Risk and Exploitability

The CVSS score of 9.3 indicates high severity. No EPSS score data is available and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is local or CI environments that install the compromised PyPI package or execute code that imports it. By controlling the package installation or execution flow, an attacker can trigger the credential harvesting functionality and extract sensitive credentials from the environment.

Generated by OpenCVE AI on May 14, 2026 at 16:22 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade PyTorch Lightning to a patched release (or to the latest stable version) that removes the credential harvesting code.
  • Rebuild or reinstall your Python environment to eliminate any cached 2.6.2 artifacts and install the verified, updated version from the official PyPI channel.
  • Configure your package manager or CI pipeline to enforce package integrity, such as requiring PyPI signing or restricting allowed versions to the patched release only.

Generated by OpenCVE AI on May 14, 2026 at 16:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-w37p-236h-pfx3 Compromise of PyTorch Lightning PyPi Package Versions
History

Thu, 14 May 2026 17:00:00 +0000

Type Values Removed Values Added
First Time appeared Lightningai
Lightningai pytorch Lightning
Vendors & Products Lightningai
Lightningai pytorch Lightning

Thu, 14 May 2026 15:15:00 +0000

Type Values Removed Values Added
Description PyTorch Lightning is a deep learning framework to pretrain and finetune AI models. Versions 2.6.2 and 2.6.2 have introduced functionality consistent with a credential harvesting mechanism.
Title Compromise of PyTorch Lightning PyPi Package Versions
Weaknesses CWE-506
References
Metrics cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Lightningai Pytorch Lightning
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-05-14T14:59:03.933Z

Reserved: 2026-05-06T17:18:51.783Z

Link: CVE-2026-44484

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-05-14T15:16:48.933

Modified: 2026-05-14T16:57:26.740

Link: CVE-2026-44484

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-14T16:45:24Z

Weaknesses