[GHSA-qqmf-gpg7-g8gw] PyTorch Lightning allows arbitrary code execution through checkpoint _instantiator hyperparameters - #9770
Conversation
There was a problem hiding this comment.
Copilot review overview
🟡 Changes recommended
The affected products still omit the vulnerable pytorch-lightning PyPI distribution.
Get a fresh assessment by requesting another Copilot review.
Review effort: Balanced
Findings: 1
Open (1)
What changed in this PR
Corrects the PyTorch Lightning advisory’s affected version and severity metadata.
Changes:
- Replaces invalid fixed version
2022.6.15with2.6.6. - Removes the CVSS v3 score.
- Updates the modification timestamp.
| File | Description |
|---|---|
GHSA-qqmf-gpg7-g8gw.json |
Corrects advisory version and severity data. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
| }, | ||
| { | ||
| "fixed": "2022.6.15" | ||
| "fixed": "2.6.6" |
|
Superseded by #9771. This PR was created through the "Suggest improvements" portal, so I'm unable to push further changes to its branch. #9771 contains the same |
4e84a2d
into
arielbosa/advisory-improvement-9770
|
Hi @arielbosa! Thank you so much for contributing to the GitHub Advisory Database. This database is free, open, and accessible to all, and it's people like you who make it great. Thanks for choosing to help others. We hope you send in more contributions in the future! |

Updates
Comments
The reported version of the lightning package does not exist.