CVE-2026-44484
Critical · CVSS 9.8PyTorch Lightning — Embedded Malicious Code / Credential Harvesting (Backdoor)
- CVSS
- 9.8
- nvd
- EPSS
- —
- KEV
- No
- Class
- other
- CWE-506, CWE-829
Description
PyTorch Lightning is a deep learning framework to pretrain and finetune AI models. Versions 2.6.2 and 2.6.2 have introduced functionality consistent with a credential harvesting mechanism.
Search profile — drives PoC discovery
Symbols pytorch_lightninglightning_aipytorch-lightningcredential harvestingGHSA-w37p-236h-pfx3
Keywords CVE-2026-44484PyTorch Lightningpytorch-lightningcredential harvestingbackdoormalicious codeCWE-506CWE-829Lightning-AI2.6.2GHSA-w37p-236h-pfx3
Versions: 2.6.2
References
Status: enriched · ingested 2026-06-30T06:00:22.000Z · profiled 2026-07-01T12:30:14.000Z