CVE-2024-48063CriticalCVSS 9.8

In PyTorch <=2.4.1, the RemoteModule has Deserialization RCE. NOTE: this is disputed by multiple parties because this is intended behavior in PyTorch distributed computing.

Published
August 7, 2026
Last Modified
—

🔗 CVE IDs covered (1)

🎯 Affected products2

  • azl3 pytorch 2.2.2-7 on Azure Linux 3.0
  • cbl2 pytorch 2.0.0-8

🔗 References (1)