PaddlePaddleGHSA-chj7-w3f6-cvfj
Code Injection in paddlepaddle
Critical9.3CVE-2024-0521 · Published Jan 20, 2024 · updated Sep 10, 2026
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| paddlepaddle PyPI | < 2.6.0 | 2.6.0 |
Details and references
The vulnerability arises from the way the url parameter is incorporated into the command string without proper validation or sanitization. If the url is constructed from untrusted sources, an attacker could potentially inject malicious commands.
- CVSS 3.0
- CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-94
- Also known as
- CVE-2024-0521, PYSEC-2026-444
More PaddlePaddle advisories
All PaddlePaddle| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Jan 32024 | PaddlePaddle floating point exception in paddle.argmin and paddle.argmax CVE-2023-52313Medium4.7fixed in 2.6.0 | Medium4.7 | 2.6.0 |
| Jan 32024 | PaddlePaddle command injection in convert_shape_compare CVE-2023-52314Critical9.6fixed in 2.6.0 | Critical9.6 | 2.6.0 |
| Jan 32024 | PaddlePaddle stack overflow in paddle.searchsorted CVE-2023-52304High8.2fixed in 2.6.0 | High8.2 | 2.6.0 |
| Jan 32024 | PaddlePaddle heap buffer overflow in paddle.repeat_interleave CVE-2023-52309High8.2fixed in 2.6.0 | High8.2 | 2.6.0 |
| Jan 32024 | PaddlePaddle stack overflow in paddle.linalg.lu_unpack CVE-2023-52307High8.2fixed in 2.6.0 | High8.2 | 2.6.0 |
| Jan 32024 | PaddlePaddle command injection in get_online_pass_interval CVE-2023-52310Critical9.6fixed in 2.6.0 | Critical9.6 | 2.6.0 |