Database/AI/ML frameworks & serving
PyTorch Lightning: RCE via deserialization of untrusted checkpoint
CVSS 9.8CVE-2024-5452AI/ML frameworks & servingcurated
Impact
RCE via deserialization of untrusted checkpoint
Who can reach it
Customer-supplied .ckpt file
What to do
Tenant-owned library. Provider action is scanning uploaded checkpoints at the object-store boundary
References
Related entries
- PyTorch Lightning: Reintroduced unsafe deserialization in 2.6.2CVE-2026-44484 · PyTorch LightningCritical
- vLLM (`AsyncEngineRPCServer`): Unsafe deserialization on RPC entrypointsCVE-2024-9053 · vLLM (`AsyncEngineRPCServer`)Critical
- BentoML (runner server): Deserialization RCE on the internal runner serverCVE-2024-9070 · BentoML (runner server)Critical
- MLflow (auth): Weak password requirementsCVE-2025-11200 · MLflow (auth)Critical
- MLflow (model creation): Directory traversal on model creationCVE-2025-11201 · MLflow (model creation)Critical
- MLflow (serving container init): Command injection in `_install_model_dependencies`CVE-2025-15379 · MLflow (serving container init)Critical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.