VDB
Sign up
—

PYSEC-2023-126

Quick fix

PYSEC-2023-126 — paddlepaddle: upgrade to the fixed version with the command below.

pip install --upgrade 'paddlepaddle>=2.5.0'

Details

PaddlePaddle before 2.5.0 has a command injection in fs.py. This resulted in the ability to execute arbitrary commands on the operating system.

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI/paddlepaddle
Introduced in: 0Fixed in: 2.5.0
Fixpip install --upgrade 'paddlepaddle>=2.5.0'

References