Developer Tools & Libraries
Remote Code Execution
Code Injection in pytorch-lightning prior to 1.6.0
Code Execution in the context of the program can be achieved in pytorch-lightning prior to v1.6.0 It is possible to execute OS commands or snippets of python code in the context of the program by…
.png)
Overview
Code Execution in the context of the program can be achieved in pytorch-lightning prior to v1.6.0
It is possible to execute OS commands or snippets of python code in the context of the program by using the PL_TRAINER_GPUS environment variable. Setting the environment variable with a malicious payload would lead to the execution of the payload thereby enabling an attacker to run their own commands in the same context as the pytorch-lightning program.
Vulnerability details
Code Execution in the context of the program can be achieved in pytorch-lightning prior to v1.6.0 It is possible to execute OS commands or snippets of python code in the context of the program by using the PL_TRAINER_GPUS environment variable.
Disclosure timeline
2022-03-03 Reported On
2022-03-04 Made Public On
2022-03-06 Fixed On
References
Credits
Debjeet Banerjee
















