CVE-2024-8019

CRITICAL

Lightning-ai/pytorch-lightning <2.3.2 - RCE

Title source: llm
STIX 2.1

Description

In lightning-ai/pytorch-lightning version 2.3.2, a vulnerability exists in the `LightningApp` when running on a Windows host. The vulnerability occurs at the `/api/v1/upload_file/` endpoint, allowing an attacker to write or overwrite arbitrary files by providing a crafted filename. This can lead to potential remote code execution (RCE) by overwriting critical files or placing malicious files in sensitive locations.

Scores

CVSS v3 9.1
EPSS 0.0210
EPSS Percentile 84.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact partial

Details

CWE
CWE-434
Status published
Products (2)
lightningai/pytorch_lightning 2.3.2
pypi/pytorch-lightning 0 - 2.4.0PyPI
Published Mar 20, 2025
Tracked Since Feb 18, 2026