CVE-2026-44484
EUVD-2026-3030314.05.2026, 15:16
PyTorch Lightning is a deep learning framework to pretrain and finetune AI models. Versions 2.6.2 and 2.6.2 have introduced functionality consistent with a credential harvesting mechanism.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| lightningai | pytorch_lightning | 2.6.2 |
| lightningai | pytorch_lightning | 2.6.3 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
- CWE-506 - Embedded Malicious CodeThe application contains code that appears to be malicious in nature.
- CWE-829 - Inclusion of Functionality from Untrusted Control SphereThe software imports, requires, or includes executable functionality (such as a library) from a source that is outside of the intended control sphere.