Skip to content
PaddlePaddleGHSA-chj7-w3f6-cvfj

Code Injection in paddlepaddle

Critical9.3CVE-2024-0521 · Published Jan 20, 2024 · updated Sep 10, 2026

GitHub advisory

Affected versions

PackageAffectedFixed in
paddlepaddle
PyPI
< 2.6.02.6.0
Details and references

The vulnerability arises from the way the url parameter is incorporated into the command string without proper validation or sanitization. If the url is constructed from untrusted sources, an attacker could potentially inject malicious commands.

CVSS 3.0
CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Severity from
GitHub (reviewed advisory)
Weakness
CWE-94
Also known as
CVE-2024-0521, PYSEC-2026-444

More PaddlePaddle advisories

All PaddlePaddle
DateAdvisory
Jan 32024PaddlePaddle floating point exception in paddle.argmin and paddle.argmax
CVE-2023-52313Medium4.7fixed in 2.6.0
Jan 32024PaddlePaddle command injection in convert_shape_compare
CVE-2023-52314Critical9.6fixed in 2.6.0
Jan 32024PaddlePaddle stack overflow in paddle.searchsorted
CVE-2023-52304High8.2fixed in 2.6.0
Jan 32024PaddlePaddle heap buffer overflow in paddle.repeat_interleave
CVE-2023-52309High8.2fixed in 2.6.0
Jan 32024PaddlePaddle stack overflow in paddle.linalg.lu_unpack
CVE-2023-52307High8.2fixed in 2.6.0
Jan 32024PaddlePaddle command injection in get_online_pass_interval
CVE-2023-52310Critical9.6fixed in 2.6.0

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.