Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2024-5452 — Detailed technical analysis of CVE-2024-5452, a remote code execution vulnerability in PyTorch Lightning via DeepDiff delta property pollution, with proof-of-concept and mitigation guidance. | Kitploit
Tools/GitHubGitHub/skrkcb2/cve-2024-5452
Vulnerability AnalysisCode AnalysisExploitationWeb Application ExploitationLearning & EducationAI Security
GitHubskrkcb2/cve-2024-5452

CVE-2024-5452

Detailed technical analysis of CVE-2024-5452, a remote code execution vulnerability in PyTorch Lightning via DeepDiff delta property pollution, with proof-of-concept and mitigation guidance.

View Repository
181 year agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2024-5452

01. Overview of RCE and pytorch-lightning

  • 1) Overview of RCE and pytorch-lightning

    RCE (Remote Code Execution) is a vulnerability that allows an attacker to execute arbitrary code remotely within a system or application, and is classified as CWE-94: Improper Control of Generation of Code ('Code Injection').

    PyTorch Lightning is a library that helps easily manage deep learning model training based on PyTorch, and DeepDiff is a library that analyzes differences by comparing two Python objects.

    CVE-2024-5452 is a vulnerability that causes RCE during deserialization through weak header validation of DeepDiff and delta attribute contamination in the process of utilizing DeepDiff and Lightning in Lightning's AI model weight-related web application features.

    Through this, we will examine the code flow that leads to vulnerabilities allowing an attacker to inject arbitrary objects or perform remote code execution (RCE), and explore countermeasures.

02. Analysis of Deserialization Vulnerability in pytorch-lightning Environment

  • 2.1 Attack Analysis Using Delta Contamination in DeepDiff

    In pytorch-lightning, among the DeepDiff endpoints of the web application source, it is possible to attack by contaminating the delta attribute and sending it to /api/v1/delta.
    Through examples, we aim to understand how contaminating the delta's dunder attributes induces an object deserialization vulnerability.

    1) Attack Flow Using Delta Contamination in DeepDiff

    The first request consists of: Client attack example, contamination setup -> Weak header validation in Deepdiff's /api/v1/delta -> State storage via contamination setup.

    Image description

    [Figure 1] POC - Endpoint attack

    Image description

    [Figure 2] POC - Vuln Injection / Full contamination setup content

    Image description

    [Figure 3] lightning/api/core/api.py / Weak header validation logic part

    Image description

    [Figure 4] lightning/api/core/app.py / Setup section

    Image description

    [Figure 5] lightning/api/core/app.py / State storage section

Download Tool