Description
PyTorch Lightning is a deep learning framework to pretrain and finetune AI models. Versions 2.6.2 and 2.6.2 have introduced functionality consistent with a credential harvesting mechanism.
Published: 2026-05-14
Score: 9.3 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

PyTorch Lightning 2.6.2 introduced code that can capture and transmit user credentials, effectively enabling credential harvesting. This weakness corresponds to CWE‑506 and CWE‑829. An attacker who can influence the installation of the compromised package or execute its code can obtain stored credentials, potentially compromising other services or data.

Affected Systems

The vulnerable product is PyTorch Lightning 2.6.2, released by Lightning‑AI. Any system that installs or imports this version from PyPI is at risk.

Risk and Exploitability

The CVSS score of 9.3 indicates high severity. No EPSS score data is available and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is local or CI environments that install the compromised PyPI package or execute code that imports it. By controlling the package installation or execution flow, an attacker can trigger the credential harvesting functionality and extract sensitive credentials from the environment.

Generated by OpenCVE AI on May 15, 2026 at 13:26 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade PyTorch Lightning to a patched release (or to the latest stable version) that removes the credential harvesting code.
  • Rebuild or reinstall your Python environment to eliminate any cached 2.6.2 artifacts and install the verified, updated version from the official PyPI channel.
  • Configure your package manager or CI pipeline to enforce package integrity, such as requiring PyPI signing or restricting allowed versions to the patched release only.

Generated by OpenCVE AI on May 15, 2026 at 13:26 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-w37p-236h-pfx3 Compromise of PyTorch Lightning PyPi Package Versions
History

Thu, 21 May 2026 20:30:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:lightningai:pytorch_lightning:2.6.2:*:*:*:*:python:*:*
cpe:2.3:a:lightningai:pytorch_lightning:2.6.3:*:*:*:*:python:*:*

Fri, 15 May 2026 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 15 May 2026 12:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-829
References
Metrics threat_severity

None

cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

threat_severity

Important


Thu, 14 May 2026 17:00:00 +0000

Type Values Removed Values Added
First Time appeared Lightningai
Lightningai pytorch Lightning
Vendors & Products Lightningai
Lightningai pytorch Lightning

Thu, 14 May 2026 15:15:00 +0000

Type Values Removed Values Added
Description PyTorch Lightning is a deep learning framework to pretrain and finetune AI models. Versions 2.6.2 and 2.6.2 have introduced functionality consistent with a credential harvesting mechanism.
Title Compromise of PyTorch Lightning PyPi Package Versions
Weaknesses CWE-506
References
Metrics cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Lightningai Pytorch Lightning
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-05-15T16:10:36.547Z

Reserved: 2026-05-06T17:18:51.783Z

Link: CVE-2026-44484

cve-icon Vulnrichment

Updated: 2026-05-15T16:09:14.693Z

cve-icon NVD

Status : Analyzed

Published: 2026-05-14T15:16:48.933

Modified: 2026-05-21T20:22:17.007

Link: CVE-2026-44484

cve-icon Redhat

Severity : Important

Publid Date: 2026-05-14T14:59:03Z

Links: CVE-2026-44484 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-05-15T13:30:45Z

Weaknesses