Credential Harvesting Vulnerability in PyTorch Lightning by Lightning AI
CVE-2026-44484
9.3CRITICAL
What is CVE-2026-44484?
PyTorch Lightning, a deep learning framework designed for pretraining and finetuning AI models, has a vulnerability that could allow malicious actors to exploit functionalities resembling a credential harvesting mechanism. This caveat was introduced in versions 2.6.2 and may expose user credentials to unauthorized access. Developers utilizing this framework should review the security advisory and take necessary precautions to safeguard sensitive information.
Affected Version(s)
pytorch-lightning 2.6.2
pytorch-lightning 2.6.3
