CRITICAL9.8
PYSEC-2026-445
PaddlePaddle vulnerable to remote code execution
Details
remote code execution in paddlepaddle/paddle 2.6.0
Are you affected?
Enter the version of the package you're using.
Affected packages
PyPI/paddlepaddle
Introduced in:
0No fixed version published yet for paddlepaddle (pip). Pin to a known-safe version or switch to an alternative.
References
- https://nvd.nist.gov/vuln/detail/CVE-2024-0917[ADVISORY]
- https://github.com/PaddlePaddle/Paddle[PACKAGE]
- https://github.com/PaddlePaddle/Paddle/blob/develop/python/paddle/distributed/fleet/utils/fs.py#L723[WEB]
- https://huntr.com/bounties/2d840735-e255-4700-9709-6f7361829119[WEB]
- https://pypi.org/project/paddlepaddle[PACKAGE]
- https://github.com/advisories/GHSA-mrmm-qmrj-xgp6[ADVISORY]