VDB
Sign up
HIGH8.8

PYSEC-2026-1756

PaddlePaddle command injection in paddle.utils.download._wget_download

Quick fix

PYSEC-2026-1756 — paddlepaddle: upgrade to the fixed version with the command below.

pip install --upgrade 'paddlepaddle>=3.0.0-beta0'

Details

Command injection in paddle.utils.download._wget_download (bypass filter) in paddlepaddle/paddle 2.6.0

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI/paddlepaddle
Introduced in: 0Fixed in: 3.0.0-beta0
Fixpip install --upgrade 'paddlepaddle>=3.0.0-beta0'

References