Skip to content
PaddlePaddleGHSA-83g7-8fch-p37m

PaddlePaddle vulnerable to code injection via winstr

Critical9.8CVE-2022-45908 · Published Nov 26, 2022 · updated Sep 10, 2026

In PaddlePaddle before 2.4, paddle.audio.functional.get_window is vulnerable to code injection because it calls eval on a user-supplied winstr. This may lead to arbitrary code execution.

GitHub advisory

Affected versions

PackageAffectedFixed in
paddlepaddle
PyPI
< 2.42.4
Details and references

More PaddlePaddle advisories

All PaddlePaddle
Advisory
Null pointer dereference in PaddlePaddle
Medium4.7Jul 26, 2023
Heap buffer overflow in PaddlePaddle
High8.3Jul 26, 2023
Float point exception (FPE) in paddlepaddle
Medium4.7Jul 26, 2023
Command injection in PaddlePaddle
Critical9.6Jul 26, 2023
PaddlePaddle vulnerable to Code Injection
Critical9.8Dec 7, 2022
PaddlePaddle Out-of-bounds Read vulnerability
Critical9.1Dec 7, 2022

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.