CVE-2026-4538 PUBLISHED

PyTorch pt2 Loading deserialization

Assigner: VulDB
Reserved: 21.03.2026 Published: 22.03.2026 Updated: 22.03.2026

A vulnerability was identified in PyTorch 2.10.0. The affected element is an unknown function of the component pt2 Loading Handler. The manipulation leads to deserialization. The attack can only be performed from a local environment. The exploit is publicly available and might be used. The project was informed of the problem early through a pull request but has not reacted yet.

Metrics

CVSS Vector: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P
CVSS Score: 4.8

Product Status

Vendor n/a
Product PyTorch
Versions
  • Version 2.10.0 is affected

Credits

  • ez-lbz (VulDB User) reporter

References

Problem Types

  • Deserialization CWE
  • Improper Input Validation CWE