PaddlePaddleGHSA-83g7-8fch-p37m
PaddlePaddle vulnerable to code injection via winstr
Critical9.8CVE-2022-45908 · Published Nov 26, 2022 · updated Sep 10, 2026
In PaddlePaddle before 2.4, paddle.audio.functional.get_window is vulnerable to code injection because it calls eval on a user-supplied winstr. This may lead to arbitrary code execution.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| paddlepaddle PyPI | < 2.4 | 2.4 |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-94
- Also known as
- CVE-2022-45908, PYSEC-2026-443
More PaddlePaddle advisories
All PaddlePaddle| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Jul 262023 | Null pointer dereference in PaddlePaddle | Medium4.7 | 2.5.0 |
| Jul 262023 | Heap buffer overflow in PaddlePaddle | High8.3 | 2.5.0 |
| Jul 262023 | Float point exception (FPE) in paddlepaddle | Medium4.7 | 2.5.0 |
| Jul 262023 | Command injection in PaddlePaddle | Critical9.6 | 2.5.0 |
| Dec 72022 | PaddlePaddle vulnerable to Code Injection | Critical9.8 | 2.4.0 |
| Dec 72022 | PaddlePaddle Out-of-bounds Read vulnerability | Critical9.1 | 2.4 |