Lightning AI patched an arbitrary code execution flaw in PyTorch Lightning's LightningModule.load_from_checkpoint path after researchers showed that a malicious checkpoint could abuse the _instantiator value stored in hyper_parameters. In affected versions through 2.6.5, the framework could import and invoke attacker-controlled Python targets during _load_state, allowing code execution when an untrusted checkpoint was loaded. The issue was tracked as CVE-2026-58659 and mapped to CWE-470, with reports noting that even torch.load(weights_only=True) did not prevent the vulnerable behavior.
The fix, merged in commit d710d689510d50e800f53b3cd773cbca20b1f86f, replaces unrestricted import resolution with an allowlist of trusted Lightning instantiator paths and raises an error for untrusted values. Project tests were added to confirm that malicious targets such as os.system are blocked while approved framework instantiators continue to function, closing a checkpoint-loading path that could otherwise let attackers weaponize shared or downloaded model artifacts.

Track how attackers are adapting to this technology.
2 events from the most recent confirmed update back to the earliest known activity.
Lightning AI merged pull request #21832 to fix the checkpoint-loading arbitrary code execution issue by limiting `_instantiator` to an allowlist of trusted import paths and rejecting untrusted values. The associated commit `d710d689510d50e800f53b3cd773cbca20b1f86f` implemented the code changes and tests blocking malicious targets such as `os.system`.
Lightning AI issue #21822 disclosed an arbitrary code execution vulnerability in Lightning/PyTorch Lightning v2.6 where an attacker-controlled `_instantiator` value in checkpoint hyperparameters could be imported and called during `LightningModule.load_from_checkpoint`. The report included a proof of concept and noted the behavior still occurred even with `torch.load(weights_only=True)` enabled.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Follow how adversaries are adapting to this technology, and where it touches your stack today.
5 references tracked. Mallory keeps watching after this page renders.
vulncheck.com
Open sourcecvefeed.io
Open sourcegithub.com
Open sourcegithub.com
Open sourcegithub.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.