CRITICAL9.8
PYSEC-2024-142
Quick fix
PYSEC-2024-142 — paddlepaddle: upgrade to the fixed version with the command below.
pip install --upgrade 'paddlepaddle>=2.6.0'Details
PaddlePaddle before 2.6.0 has a command injection in get_online_pass_interval. This resulted in the ability to execute arbitrary commands on the operating system.
Are you affected?
Enter the version of the package you're using.