Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-6932 | In lightning-ai/pytorch-lightning version 2.3.2, a vulnerability exists in the `LightningApp` when running on a Windows host. The vulnerability occurs at the `/api/v1/upload_file/` endpoint, allowing an attacker to write or overwrite arbitrary files by providing a crafted filename. This can lead to potential remote code execution (RCE) by overwriting critical files or placing malicious files in sensitive locations. |
Github GHSA |
GHSA-4cv3-v7pv-rfhf | PyTorch Lightning path traversal vulnerability |
Fri, 01 Aug 2025 01:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Lightningai
Lightningai pytorch Lightning |
|
| CPEs | cpe:2.3:a:lightningai:pytorch_lightning:2.3.2:*:*:*:*:python:*:* | |
| Vendors & Products |
Lightningai
Lightningai pytorch Lightning |
|
| Metrics |
cvssV3_1
|
Thu, 20 Mar 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 20 Mar 2025 10:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In lightning-ai/pytorch-lightning version 2.3.2, a vulnerability exists in the `LightningApp` when running on a Windows host. The vulnerability occurs at the `/api/v1/upload_file/` endpoint, allowing an attacker to write or overwrite arbitrary files by providing a crafted filename. This can lead to potential remote code execution (RCE) by overwriting critical files or placing malicious files in sensitive locations. | |
| Title | Arbitrary File Write/Overwrite in lightning-ai/pytorch-lightning | |
| Weaknesses | CWE-434 | |
| References |
| |
| Metrics |
cvssV3_0
|
Status: PUBLISHED
Assigner: @huntr_ai
Published:
Updated: 2025-03-20T19:02:39.949Z
Reserved: 2024-08-20T17:11:51.086Z
Link: CVE-2024-8019
Updated: 2025-03-20T17:54:53.521Z
Status : Analyzed
Published: 2025-03-20T10:15:39.010
Modified: 2025-08-01T01:42:57.723
Link: CVE-2024-8019
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA