CVE-2026-4538 MEDIUM

CVE-2026-4538: PyTorch pt2 Loading deserialization

Vendor N/A
Product PyTorch
Weakness CWE-502 · Unsafe deserialization
Published March 22, 2026
Last update March 23, 2026

CVSS base score

4.8/10
Attack vector Local
Attack complexity Low
Privileges required Low
User interaction None
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P

What the vulnerability does

01Description

A vulnerability was identified in PyTorch 2.10.0. The affected element is an unknown function of the component pt2 Loading Handler. The manipulation leads to deserialization. The attack can only be performed from a local environment. The exploit is publicly available and might be used. The project was informed of the problem early through a pull request but has not reacted yet.

Key dates

02Disclosure timeline

March 22, 2026 CVE published
March 23, 2026 Record updated