Skip to content
PaddlePaddleGHSA-gcjf-29m9-888q

PaddlePaddle vulnerable to Code Injection

Critical9.8CVE-2022-46742 · Published Dec 7, 2022 · updated Sep 10, 2026

GitHub advisory

Affected versions

PackageAffectedFixed in
paddlepaddle
PyPI
< 2.4.02.4.0
Details and references

Code injection in `paddle.audio.functional.get_window` in PaddlePaddle 2.4.0-rc0 allows arbitrary code execution. A [patch](https://github.com/PaddlePaddle/Paddle/commit/26c419ca386aeae3c461faf2b828d00b48e908eb) is available on the `develop` branch of the repository and anticipated to be part of a 2.4 release.

CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Severity from
GitHub (reviewed advisory)
Weakness
CWE-94
Also known as
CVE-2022-46742, PYSEC-2022-43063

More PaddlePaddle advisories

All PaddlePaddle
DateAdvisory
Dec 72022PaddlePaddle Out-of-bounds Read vulnerability
CVE-2022-46741Critical9.1fixed in 2.4
Nov 262022PaddlePaddle vulnerable to code injection via winstr
CVE-2022-45908Critical9.8fixed in 2.4
Jul 262023Use after free in PaddlePaddle
CVE-2023-38669High8.3fixed in 2.5.0
Jul 262023Command injection in PaddlePaddle
CVE-2023-38673Critical9.6fixed in 2.5.0
Jul 262023Float point exception (FPE) in paddlepaddle
CVE-2023-38672Medium4.7fixed in 2.5.0
Jul 262023Heap buffer overflow in PaddlePaddle
CVE-2023-38671High8.3fixed in 2.5.0

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.