lightning is vulnerable to Unrestricted Upload of File with Dangerous Type
91
Critical Risk
A vulnerability in the /v1/runs API endpoint of lightning-ai/pytorch-lightning allows attackers to exploit path traversal when extracting tar.gz files. When the LightningApp runs with the plugin_server, attackers can deploy malicious tar.gz plugins that embed arbitrary files with path traversal vulnerabilities. This can lead to arbitrary files being written to any directory on the victim's local file system, potentially enabling Remote Code Execution (RCE).
You are affected if you are using a vulnerable version of the package.
lightning is vulnerable to Unrestricted Upload of File with Dangerous Type in versions 0.2 - 2.3.2.
Upgrade lightning to a patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant