"Critical PyTorch Vulnerability Can Lead to Sensitive AI Data Theft"
"Critical PyTorch Vulnerability Can Lead to Sensitive AI Data Theft"
Security researchers at Huntr discovered a critical-severity vulnerability in the PyTorch machine learning library that could be exploited for remote code execution. The vulnerability CVE-2024-5480 impacts the distributed RPC (Remote Procedure Call) framework of PyTorch. The researchers said that the issue exists because the framework does not verify the functions called during RPC operations.