Skip to content
PaddlePaddleGHSA-9q9v-qgwx-84mr

Command injection in PaddlePaddle

Critical9.6CVE-2023-38673 · Published Jul 26, 2023 · updated Sep 10, 2026

PaddlePaddle before 2.5.0 has a command injection in fs.py. This resulted in the ability to execute arbitrary commands on the operating system.

GitHub advisory

Affected versions

PackageAffectedFixed in
paddlepaddle
PyPI
< 2.5.02.5.0
Details and references

More PaddlePaddle advisories

All PaddlePaddle
Advisory
PaddlePaddle segfault in paddle.dot
Medium4.7Jan 3, 2024
PaddlePaddle floating point exception in paddle.nanmedian
Medium4.7Jan 3, 2024
Use after free in PaddlePaddle
High8.3Jul 26, 2023
Float point exception (FPE) in paddlepaddle
Medium4.7Jul 26, 2023
Heap buffer overflow in PaddlePaddle
High8.3Jul 26, 2023
Null pointer dereference in PaddlePaddle
Medium4.7Jul 26, 2023

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.