logo

Safety Broken: PyTorch “Safe” Mode Bypassed by Critical RCE Flaw

ID: b34a3e6c-9f1b-5933-a89d-3f530a6d3184

STIX ID: report--b34a3e6c-9f1b-5933-a89d-3f530a6d3184

Feed Name: securityonline.info

Threat Score
78/100

Date Published: 2026-01-29

Date Updated: 2026-04-23

Author: Ddos

...
...

PyTorch patched a high-severity vulnerability (CVE-2026-24747, CVSS 8.8) in the weights_only=True unpickler that could allow arbitrary code execution via crafted model checkpoint (.pth) files by exploiting improper validation of pickle opcodes and storage metadata; the flaw affects PyTorch <= 2.9.1 and is fixed in 2.10.0, and users are urged to update immediately to mitigate AI supply-chain risk.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.