CVE Wiki Pixee · CVE intelligence
← All CVEs

CVE-2026-44484

Critical · CVSS 9.8

PyTorch Lightning — Embedded Malicious Code / Credential Harvesting (Backdoor)

CVSS
9.8
nvd
EPSS
KEV
No
Class
other
CWE-506, CWE-829

Description

PyTorch Lightning is a deep learning framework to pretrain and finetune AI models. Versions 2.6.2 and 2.6.2 have introduced functionality consistent with a credential harvesting mechanism.

Search profile — drives PoC discovery

Symbols pytorch_lightninglightning_aipytorch-lightningcredential harvestingGHSA-w37p-236h-pfx3
Keywords CVE-2026-44484PyTorch Lightningpytorch-lightningcredential harvestingbackdoormalicious codeCWE-506CWE-829Lightning-AI2.6.2GHSA-w37p-236h-pfx3
Versions: 2.6.2

References

Status: enriched · ingested 2026-06-30T06:00:22.000Z · profiled 2026-07-01T12:30:14.000Z