CRITICAL9.1
PYSEC-2026-442
PaddlePaddle Path Traversal vulnerability
Details
Arbitrary File Overwrite Via Path Traversal in paddlepaddle/paddle before 2.6
Are you affected?
Enter the version of the package you're using.
Affected packages
PyPI/paddlepaddle
Introduced in:
0No fixed version published yet for paddlepaddle (pip). Pin to a known-safe version or switch to an alternative.
References
- https://nvd.nist.gov/vuln/detail/CVE-2024-0818[ADVISORY]
- https://github.com/PaddlePaddle/Paddle/commit/5c50d1a8b97b310cbc36560ec36d8377d6f29d7c[WEB]
- https://github.com/PaddlePaddle/Paddle[PACKAGE]
- https://huntr.com/bounties/85b06a1b-ac0b-4096-a06d-330891570cd9[WEB]
- https://pypi.org/project/paddlepaddle[PACKAGE]
- https://github.com/advisories/GHSA-2rp8-hff9-c5wr[ADVISORY]