Bounties
Partners
Community
Info
pytorch / pytorch
Project repository
Tensors and Dynamic neural networks in Python with strong GPU acceleration
Submit a report
FIRST INTERACTION
WITHIN
N/A DAYS
REVIEW
WITHIN
19 DAYS
FIX
WITHIN
N/A DAYS
`torch.export.load()` RCE via unsanitized `guards_code` strings executed by `exe...
May 8th 2026
11x-x11
•
duplicate
High
RCE via torch.load(weights_only=False) in PT2 archive loading — use_pickle flag...
Apr 12th 2026
snakeyworm
•
duplicate
None
Arbitrary Code Execution via Insecure Deserialization in torch.hub.load_state_di...
Apr 11th 2026
finddabugs
•
duplicate
High
PyTorch torch.hub.load_state_dict_from_url() Untrusted Deserialization Remote Co...
Apr 11th 2026
yamemres
•
duplicate
Critical
`weights_only=False` Silent Fallback in ExportedProgram Deserialization — RCE vi...
May 8th 2026
jtjisgod
•
duplicate
High
Incorrect Default Permissions
Apr 30th 2026
projectworks007
•
self closed
Remote Code Execution via `load_state_dict_from_url` Defaulting to `weights_only...
Apr 11th 2026
buttergolemcode
•
duplicate
High
Unsafe Pickle Deserialization in Distributed Checkpoint Metadata Loading Allows...
Mar 16th 2026
elucidator-hky
•
self closed
Unauthenticated RCE via TensorPipe RPC agent pickle deserialization on network l...
Mar 15th 2026
eistee82
•
self closed
Unsafe eval() of cached guard expressions in Inductor/AOTAutograd cache enables...
Mar 16th 2026
elucidator-hky
•
self closed
Unsafe pickle.loads() and torch.load(weights_only=False) in DataPipe Decoder, Ch...
Mar 16th 2026
elucidator-hky
•
self closed
Full SSRF + Reflected XSS via TCPStore Poisoning in torch.distributed.debug
Mar 17th 2026
mscgo
•
self closed
Unsafe default deserialization path in RoutedDecoder allows code execution from...
Mar 3rd 2026
4ur0n
•
self closed
PyTorch FileStore Path Traversal Allows Arbitrary File Write Outside Sandbox
Mar 9th 2026
amadhan882
•
self closed
Arbitrary Code Execution via Unsanitized pickle.load() in Distributed Checkpoint...
Feb 22nd 2026
wernerina
•
duplicate
High
Arbitrary Code Execution in torch.distributed.checkpoint.load() via Unsafe Pickl...
Feb 19th 2026
eigentum
•
duplicate
Critical
Arbitrary Memory Corruption and DoS via Out-of-Bounds Sparse Tensor Deserializat...
May 16th 2026
catalyzer9867
•
duplicate
High
Unauthenticated Remote Code Execution (RCE) via State Machine Bypass in torch.di...
Apr 15th 2026
catalyzer9867
•
self closed
Command Injection in PyTorch Dynamo Benchmark Runner
May 15th 2026
alrightryanx
•
pending
Insecure Deserialization via pickle.loads() in PyTorch DataPipes Decoder
May 13th 2026
galanzi2580-wq
•
pending
Remote Code Execution via eval() on Untrusted Dump Data in PyTorch Flight Record...
May 13th 2026
galanzi2580-wq
•
pending
Command injection via unsanitized compiler flags in `torch.utils.cpp_extension`...
May 12th 2026
l1iith
•
pending
Zip Slip arbitrary file write via unsafe extractall() in torch.export.experiment...
May 12th 2026
l1iith
•
pending
Remote Code Execution (RCE) via Insecure Pickle Deserialization in torch.load
May 12th 2026
sebas5207418
•
pending
Out-of-bounds read via unchecked class_type() index in flatbuffer module loader
Feb 13th 2026
jeongmin-choi00
•
self closed
Zip Slip arbitrary file write in torch.hub.load_state_dict_from_url() legacy zip...
May 3rd 2026
theagentknownasren-gif
•
pending
Zip Slip arbitrary file write in torch.hub.load_state_dict_from_url() legacy zip...
May 3rd 2026
theagentknownasren-gif
•
pending
PyTorch Quantization Extreme Scale NaN Corruption - DoS via Model Corruption
Jan 30th 2026
spamblue890-oss
•
self closed
Path Traversal in DirectoryReader
Apr 27th 2026
yashvardhantrip
•
pending
Remote Code Execution via unsafe pickle.loads() in DataPipes basichandlers()
Apr 26th 2026
red-base
•
pending
PyTorch `weights_only=True` Remote Code Execution Vulnerability
Jan 18th 2026
orenyomtov
•
duplicate
High
DoS via Unbounded Memory Allocation in Sparse Tensor Deserialization (weights_on...
Apr 17th 2026
ahmetartuc
•
pending
PyTorch torch.cuda.memory_viz CLI: pickle.load() on user-controlled input leads...
Jan 11th 2026
nn0nkey
•
duplicate
High
PyTorch's `DefaultLoadPlanner` torch.load(weights_only=False) leads to Remote Co...
Jan 11th 2026
nn0nkey
•
duplicate
High
Remote Code Execution in torch.export.load via Unsafe Deserialization
Dec 16th 2025
daddyjamwal
•
duplicate
High
Permanent Denial of Service (DoS) via _ntuple_from_first
Mar 13th 2026
janetcohen
•
pending
Unsafe fallback in deserialize_torch_artifact enables RCE despite weights_only=T...
Apr 2nd 2026
pandas0531
•
self closed
PyTorch PGO Remote Cache Deserialization Vulnerability
Jan 11th 2026
cherno-x
•
duplicate
Critical
Command Injection in torch.jit.annotations.parse_type_line
Feb 10th 2026
decadeofdata
•
pending
RCE via TorchScript Deserialization in PyTorch
Feb 9th 2026
lau90eth
•
pending
Out-of-Bounds Memory Write Affecting Pytorch Deserialization
Feb 2nd 2026
kattraxler
•
pending
Out-of-Bounds Memory Read Affecting Pytorch Deserialization
Feb 2nd 2026
kattraxler
•
pending
Arbitrary Code Execution via Insecure Deserialization in torch.load()
Feb 1st 2026
yousefabdelmohymen
•
duplicate
High
PyTorch torch.load(..., weights_only=False) can lead to RCE
Nov 6th 2025
bertram2000
•
duplicate
Critical
Add out_dtype parameter support to torch.einsum
Jan 10th 2026
rudymentale
•
pending
NULL Pointer Dereference in PyTorch Third-party Miniz Library Examples
Jan 1st 2026
vutuanviet123
•
pending
CSV Injection Vulnerabilities in PyTorch Benchmarking Utilities
Dec 31st 2025
vutuanviet123
•
pending
Server-Side Request Forgery (SSRF) Vulnerabilities in PyTorch Statistics Upload...
Dec 31st 2025
vutuanviet123
•
pending
Command Injection Vulnerabilities in PyTorch C++ Extension Compiler Detection an...
Dec 31st 2025
vutuanviet123
•
pending
Remote Code Execution via Unsafe Deserialization in PyTorch Model Debugging and...
Dec 16th 2025
vutuanviet123
•
duplicate
Critical
Remote Code Execution via Unsafe Deserialization in PyTorch Model Debugging and...
Oct 2nd 2025
vutuanviet123
•
self closed
Command Injection Vulnerabilities in PyTorch C++ Extension Compiler Detection
Oct 2nd 2025
vutuanviet123
•
self closed
Division By Zero Vulnerability in PyTorch Loss Functions
Dec 31st 2025
vutuanviet123
•
pending
Path Traversal Vulnerability in PyTorch CUDA Kernels Generation
Dec 31st 2025
vutuanviet123
•
pending
Arbitrary Code Execution via pickle.load() in Distributed Checkpoint Loading
Oct 1st 2025
perfecxion-ai
•
self closed
Silent incorrect gradient
Dec 25th 2025
shemshallah
•
pending
Numerical instability
Dec 25th 2025
shemshallah
•
pending
Numerical instability
Dec 25th 2025
shemshallah
•
pending
torch.package Path-Traversal Enables Arbitrary File Write
Aug 15th 2025
ashmitsh4rma
•
self closed
Denial of Service via Excessive GPU/CPU Memory Allocation in torch.nested.to_pad...
Sep 25th 2025
joelindra
•
pending
CUDA GPU-side buffer overflow (arbitrary-write within 2 GiB)
Jun 8th 2025
jwnhy
•
pending
Script injection for loading remote models using "torch.hub.load"
Mar 31st 2025
l1k3beef
•
pending
Data Corruption in PyTorch functionalize Due to Expired Pointer Dereference with...
Mar 27th 2025
ashfiexe
•
pending
The pytorch/torch/distributed/rpc/__init__.py file can be modified locally, lead...
Nov 9th 2024
hexian2001
•
informative
High
PyTorch Distributed RPC Framework rpc.remote has Deserialization RCE
Oct 7th 2024
hexian2001
•
self closed
Deserialization of untrusted data in Pytorch RPC Framework
Sep 25th 2024
xbalien
•
Critical
•
$1500
Critical
•
$1500
•
CVE-2024-7804
CVE-2024-7804
Command injection via unsafe pickle.loads in torch.utils.model_dump
Jul 8th 2024
sunrisexu
•
informative
High
Command injection in release_notes/common.py
Jul 8th 2024
kr3ww
•
informative
Critical
Insecure Temporary File
May 23rd 2024
h2oa
•
not applicable
PyTorch Distributed RPC Framework Remote Code Execution
May 31st 2024
xbalien
•
Critical
•
$1500
Critical
•
$1500
•
CVE-2024-5480
CVE-2024-5480
jinja2 autoescape not enabled
Nov 22nd 2023
dmandefy
•
informative
High
Remote Code Execution (RCE)
Oct 5th 2023
ready-research
•
self closed
ReDOS
Mar 23rd 2023
mtrill47
•
self closed
Classic buffer overflow in "torch_shm_manager"
Feb 19th 2023
ewa-kr
•
informative
High
torch.hub.load_state_dict_from_url is vulnerable to RCE if malicious file is imp...
Jan 3rd 2023
c3l3si4n
•
informative
High
Command Injection in PyTorch
Dec 27th 2022
danmcinerney
•
not applicable
XSS in Caffe2's Flask App included in PyTorch
Dec 21st 2022
danmcinerney
•
pending
Deserialization of Untrusted Data
Jun 29th 2021
asjidkalam
•
pending
Code Injection
Dec 21st 2020
b3ef
•
pending
CRITICAL
$1500
HIGH
$750
MEDIUM
$125
LOW
$20