{"id":"GHSA-qqv2-35q8-p2g2","summary":"PaddlePaddle command injection in paddle.utils.download._wget_download ","details":"Command injection in paddle.utils.download._wget_download (bypass filter) in paddlepaddle/paddle 2.6.0","aliases":["CVE-2024-0815","PYSEC-2026-1756"],"modified":"2026-08-24T00:35:34.744587917Z","published":"2024-03-07T06:30:30Z","database_specific":{"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2024-03-07T17:24:49Z","nvd_published_at":"2024-03-07T04:15:07Z","cwe_ids":["CWE-78"]},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-0815"},{"type":"WEB","url":"https://github.com/PaddlePaddle/Paddle/commit/4c0888d7b8f10405e2e79adc41c224264f93e816"},{"type":"PACKAGE","url":"https://github.com/PaddlePaddle/Paddle"},{"type":"WEB","url":"https://huntr.com/bounties/83bf8191-b259-4b24-8ec9-0115d7c05350"}],"affected":[{"package":{"name":"paddlepaddle","ecosystem":"PyPI","purl":"pkg:pypi/paddlepaddle"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"2.6.0"}]}],"versions":["1.8.5"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/03/GHSA-qqv2-35q8-p2g2/GHSA-qqv2-35q8-p2g2.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"}]}