{"id":"CVE-2022-0845","aliases":["GHSA-r5qj-cvf9-p85h","PYSEC-2022-181","PYSEC-2026-3969"],"url":"https://o3.security/vulnerability/CVE-2022-0845","summary":"Code Injection in pytorchlightning/pytorch-lightning","details":"PyTorch Lightning version 1.5.10 and prior is vulnerable to code injection. An attacker could execute commands on the target OS running the operating system by setting the `PL_TRAINER_GPUS` when using the `Trainer` module. A [patch](https://github.com/pytorchlightning/pytorch-lightning/commit/8b7a12c52e52a06408e9231647839ddb4665e8ae) is included in the `1.6.0` release.","published":"2022-03-05T21:25:09Z","modified":"2026-09-10T17:26:06.105487760Z","cvss":{"score":7.3,"severity":"HIGH","vector":"CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:L"},"epss":{"score":0.0098,"percentile":0.59076,"asOf":"2026-08-23"},"cisaKev":null,"exploitsKnown":1,"affectedPackages":[{"ecosystem":"PyPI","name":"pytorch-lightning","fixedVersion":"1.6.0"}],"fix":{"url":"https://github.com/pytorchlightning/pytorch-lightning/commit/8b7a12c52e52a06408e9231647839ddb4665e8ae","label":"pytorchlightning/pytorch-lightning@8b7a12c"},"references":[{"type":"WEB","url":"https://huntr.dev/bounties/a795bf93-c91e-4c79-aae8-f7d8bda92e2a"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/0xxx/CVE-2022-0845.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-0845"},{"type":"FIX","url":"https://github.com/pytorchlightning/pytorch-lightning/commit/8b7a12c52e52a06408e9231647839ddb4665e8ae"},{"type":"WEB","url":"https://github.com/PyTorchLightning/pytorch-lightning/pull/12212"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-r5qj-cvf9-p85h"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/pytorch-lightning/PYSEC-2022-181.yaml"},{"type":"WEB","url":"https://github.com/pytorchlightning/pytorch-lightning"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-09-10T17:26:06.105487760Z"}}