HIGH8.8
PYSEC-2026-1756
PaddlePaddle command injection in paddle.utils.download._wget_download
Quick fix
PYSEC-2026-1756 — paddlepaddle: upgrade to the fixed version with the command below.
pip install --upgrade 'paddlepaddle>=3.0.0-beta0'Details
Command injection in paddle.utils.download._wget_download (bypass filter) in paddlepaddle/paddle 2.6.0
Are you affected?
Enter the version of the package you're using.
Affected packages
PyPI/paddlepaddle
Introduced in:
0Fixed in: 3.0.0-beta0Fix
pip install --upgrade 'paddlepaddle>=3.0.0-beta0'References
- https://nvd.nist.gov/vuln/detail/CVE-2024-0815[ADVISORY]
- https://github.com/PaddlePaddle/Paddle/commit/4c0888d7b8f10405e2e79adc41c224264f93e816[FIX]
- https://github.com/PaddlePaddle/Paddle[PACKAGE]
- https://huntr.com/bounties/83bf8191-b259-4b24-8ec9-0115d7c05350[WEB]
- https://pypi.org/project/paddlepaddle[PACKAGE]
- https://github.com/advisories/GHSA-qqv2-35q8-p2g2[ADVISORY]