Fix lightning fixed version (2.6.6) and add pytorch-lightning to GHSA-qqmf-gpg7-g8gw - #9660
Conversation
There was a problem hiding this comment.
Copilot review overview
🟢 Approval recommended
The updated ranges are schema-consistent and align with the advisory’s stated first fixed release.
Review effort: Balanced
Findings: None
What changed in this PR
Corrects affected-version metadata for the PyTorch Lightning checkpoint RCE.
Changes:
- Sets
lightningfixed version to2.6.6. - Adds
pytorch-lightningas affected through2.6.5.
| File | Description |
|---|---|
advisories/github-reviewed/2026/07/GHSA-qqmf-gpg7-g8gw/GHSA-qqmf-gpg7-g8gw.json |
Corrects and expands affected package ranges. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
|
Independent confirmation from released artifacts (not advisory metadata), in case it helps this get merged — the main objection to correcting a Grep the shipped wheels for the allowlist the fix introduces: u=$(curl -s https://pypi.org/pypi/lightning/2.6.6/json | jq -r '.urls[]|select(.packagetype=="bdist_wheel").url')
curl -sL -o li.whl "$u"; unzip -p li.whl lightning/pytorch/core/saving.py | grep -c _ALLOWED_INSTANTIATORS
Same git-ancestry trap as described above: Two more points that support the change:
+1 on this PR as-is. |
db09a8e
into
github:drago-balto/advisory-improvement-9660
|
Hi @drago-balto! Thank you so much for contributing to the GitHub Advisory Database. This database is free, open, and accessible to all, and it's people like you who make it great. Thanks for choosing to help others. We hope you send in more contributions in the future! |
Summary
This corrects the fixed-version data in GHSA-qqmf-gpg7-g8gw (CVE-2026-58659, PyTorch Lightning checkpoint RCE).
The advisory currently records the
lightningfix as2022.6.15. No such release of the modernlightningpackage exists; that string is a date-style version from the legacypytorch-lightningversioning era and sorts as newer than every real 2.x release. As a result, every actually-fixed version (2.6.6 and up) is still reported as vulnerable, and there is no installable version a consumer can upgrade to that satisfies the range.Changes
lightning: correct the fixed version from2022.6.15to2.6.6.pytorch-lightning(PyPI) as an affected package, fixed in2.6.6. Both distributions ship the same vulnerablepytorch_lightningcode (_load_state/LightningModule.load_from_checkpoint) and are fixed by the same change.Supporting public references
detailsstate the flaw exists "through 2.6.5, fixed in commit d710d68" — i.e. 2.6.6 is the first fixed release.lightning) recordsfixed: 2.6.6: https://github.com/pypa/advisory-database/tree/main/vulns/lightning/PYSEC-2026-3624.yamlpytorch-lightning) likewise recordsfixed: 2.6.6._instantiatorinload_from_checkpointLightning-AI/pytorch-lightning#21832 and commit Lightning-AI/pytorch-lightning@d710d68The fix commit was cherry-picked to the release branch, so it is not a linear git ancestor of the
2.6.6tag; the version-based fixed value (2.6.6) is the authoritative one and matches the PYSEC records cross-referenced from this advisory.Change follows the OSV schema and touches only this one advisory.