CVE-2026-24747Disclosure(linuxfoundation / pytorch)

MEDIUMCVSS 8.8 · HIGH

Exploit discussion active in current signal (2 latest mentions)

Immediate actions

  • Patch linuxfoundation pytorch systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

PyTorch is a Python package that provides tensor computation. Prior to version 2.10.0, a vulnerability in PyTorch's `weights_only` unpickler allows an attacker to craft a malicious checkpoint file (`.pth`) that, when loaded with `torch.load(..., weights_only=True)`, can corrupt memory and potentially lead to arbitrary code execution. Version 2.10.0 fixes the issue.

4.3/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-94CWE-502

Priority

MEDIUM

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • pytorch

Threat summary

  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 12 mentions across 8 observed days
  • Momentum state: stable

What's happening

  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 2 signals
  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 10 signals
  • Disclosure: 5 classified signals
  • General: 3 classified signals
  • Peaked 6d ago at 3 mentions (2026-01-28); latest day: 2
  • 12 total mentions across 8 days

Affected systems

Products
pytorch

Deep dive

Activity timeline12 mentions / 8d
01223Mentions · 2026-01-27: 2Mentions · 2026-01-28: 3Mentions · 2026-01-30: 1Mentions · 2026-03-03: 1Mentions · 2026-03-04: 1Mentions · 2026-03-07: 1Mentions · 2026-07-01: 1Mentions · 2026-09-01: 2PoC Mentioned / Linked · 2026-01-30: 1PoC Mentioned / Linked · 2026-03-04: 1Exploit Tool / Code · 2026-03-04: 1Patch / Workaround · 2026-01-28: 2Technical Details · 2026-01-27: 2Technical Details · 2026-01-28: 3Technical Details · 2026-01-30: 1Technical Details · 2026-03-03: 1Technical Details · 2026-03-07: 1Technical Details · 2026-07-01: 1Technical Details · 2026-09-01: 101-2701-2801-3003-0303-0403-0707-0109-01
Signal classification5 categories
Disclosure
541.7%
General
325.0%
Patch
216.7%
PoC
18.3%
Exploit
18.3%
Referenced assets7 URLs
Classification over time
DateTotalLabels
2026-01-272
Disclosure2
2026-01-283
Disclosure1Patch2
2026-01-301
PoC1
2026-03-031
Disclosure1
2026-03-041
Exploit1
2026-03-071
General1
2026-07-011
Disclosure1
2026-09-012
General2
Full discourse12 posts
  • Giuseppe `N3mes1s`@N3mes1s
    General

    I found the same pattern for the CVE-2026-24747 RCE. I had to push opus 4.6 around 10 research sessions and multiple double check and pus for primitives and deep code understanding before be able to produce the exploit. I would say in a complex scenario is 10X complicated

    Post summary

    The author indicates their research led to an exploit for CVE-2026-24747, clarifying the issue as an RCE, but no PoC, code, or patch details are provided.

    180834511.9K
    12.8K followersView on X
  • Azrael@azraelxuemo
    PoC

    RCE video demo of cve-2026-24747 https://t.co/z2zKkqfkU6

    Post summary

    A video demo illustrating remote code execution for CVE‑2026‑24747 is shared, serving as a proof of concept without mentioning exploitation tools, patches, or active attacks.

    08046203.7K
    149 followersView on X
  • Giuseppe `N3mes1s`@N3mes1s
    Exploit

    And we have a fully weaponized CVE-2026-24747 The victim does only: torch.load(open("evil.pth","rb"), weights_only=True) #pruva https://t.co/r4piOmrYYB

    Post summary

    The tweet claims that CVE-2026-24747 is fully weaponized, providing a basic code snippet that demonstrates how to exploit the flaw via PyTorch's torch.load, but it offers no patch info or evidence of wild exploitation.

    03034134.0K
    12.8K followersView on X
  • Simone Margaritelli@evilsocket
    Disclosure

    AI ( Pruva ) is very close to fully weaponize CVE-2026-24747, with RCE on any service that supports uploading and running a PyTorch model, regardless of security hardening ( weights_only=True ).

    Post summary

    The entry announces that CVE-2026-24747 can lead to remote code execution on any service running PyTorch models, overriding security hardening settings.

    01022113.6K
    47.5K followersView on X
  • Azrael@azraelxuemo
    General

    The story behind the CVE-2026-24747 PyTorch weights_only bypass

    Post summary

    The snippet references CVE-2026-24747 involving a PyTorch weights_only bypass but provides no further details on exploitation, mitigation, or technical specifics.

    6002162.1K
    207 followersView on X
  • deepsec.cc@deepsec_cc
    Disclosure

    #deepsec "One Chain to Own Them All: Breaking AI Infrastructures". weights_only is the protection everyone leans on. @azraelxuemo & @llfamsec got past it — one heap overflow (CVE-2026-24747) hitting vLLM, ComfyUI, Elasticsearch & more, on default configs. https://deepsec.cc/202607/speaker-jian-zhou-lei-lu.html

    Post summary

    DeepSec disclosed a heap overflow (CVE-2026-24747) impacting multiple AI infrastructure tools on default configurations; no PoC, exploit code, or active exploitation details were provided.

    0001141.3K
    556 followersView on X
  • Azrael@azraelxuemo
    General

    1. When I discovered CVE-2026-24747 last year, I initially thought it wasn't very exploitable. Although it had a write primitive, it lacked a leak, so for a while I considered it a useless vulnerability.

    Post summary

    The author shares a personal assessment that CVE-2026-24747, while having a write primitive, may be non-exploitable due to lacking a memory leak, but no further details or exploit code are given.

    00010192
    203 followersView on X
  • PulsePatch.io@pulsepatchio
    Patch

    PyTorch is vulnerable to remote code execution via untrusted checkpoint files (CVE-2026-24747). Review your model loading practices and consider updating. #PyTorch #RCE #infosec https://www.pulsepatch.io/posts/cve-2026-24747-pytorch-remote-code-execution

    Post summary

    The post highlights a remote code execution flaw in PyTorch and advises users to update their installations to mitigate the risk.

    0000095
    1 followersView on X
  • PulsePatch.io@pulsepatchio
    Patch

    PyTorch versions prior to 2.10.0 are vulnerable to arbitrary code execution via malicious .pth checkpoint files (CVE-2026-24747). Load trusted models only. #PyTorch #MachineLearning #infosec https://www.pulsepatch.io/posts/pytorch-weights-only-unpickler-rce-cve-2026-24747

    Post summary

    PyTorch versions below 2.10.0 are vulnerable to arbitrary code execution when loading malicious .pth checkpoint files; users are advised to only load trusted models, with details hosted on PulsePatch.

    0000085
    1 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-24747 Memory Corruption and Code Execution Vulnerability in PyTorch Bef... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-24747 Customizable Vulnerability Alerts: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=4

    Post summary

    The tweet announces CVE-2026-24747, a memory corruption and code execution flaw in PyTorch, and links to a details page but provides no PoC, exploit, or patch information.

    0000059
    4.0K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-24747 PyTorch is a Python package that provides tensor computation. Prior to version 2.10.0, a vulnerability in PyTorch's `weights_only` unpickler allows an attacker to cra… https://www.cve.org/CVERecord?id=CVE-2026-24747

    Post summary

    The CVE-2026-24747 entry highlights a flaw in PyTorch's weights_only unpickler, enabling malicious payload crafting before v2.10.0, with no evidence of active exploitation, patches, or PoC references.

    00000296
    56.5K followersView on X
  • cvereports@_cvereports
    Disclosure

    CVE-2026-24747: Heavy Weights: Crushing PyTorch's 'Secure' Loader via Heap Corruption A critical heap corruption vulnerability in PyTorch's restricted unpickler allows attackers to bypass the `weights_only=True` security flag, turning safe model loadi... https://cvereports.com/reports/CVE-2026-24747

    Post summary

    A critical heap corruption vulnerability in PyTorch's restricted unpickler has been disclosed, enabling attackers to bypass the weights_only security flag used for safe model loading.

    0000059
    29 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Applinuxfoundationpytorch-python-

Explore more