HIGH7.8
PYSEC-2026-1754
PaddlePaddle command injection vulnerability
Quick fix
PYSEC-2026-1754 — paddlepaddle: upgrade to the fixed version with the command below.
pip install --upgrade 'paddlepaddle>=3.0.0-beta0'Details
Command injection in IrGraph.draw in paddlepaddle/paddle 2.6.0
Are you affected?
Enter the version of the package you're using.
Affected packages
PyPI/paddlepaddle
Introduced in:
0Fixed in: 3.0.0-beta0Fix
pip install --upgrade 'paddlepaddle>=3.0.0-beta0'References
- https://nvd.nist.gov/vuln/detail/CVE-2024-0817[ADVISORY]
- https://github.com/PaddlePaddle/Paddle/commit/bdf6234fdc22e6ee7948950d271cbbe1d27edc93[FIX]
- https://github.com/PaddlePaddle/Paddle[PACKAGE]
- https://huntr.com/bounties/44d5cbd9-a046-417b-a8d4-bea6fda9cbe3[WEB]
- https://pypi.org/project/paddlepaddle[PACKAGE]
- https://github.com/advisories/GHSA-fh54-3vhg-mpc2[ADVISORY]