Launch Week Day 1: Announcing Security Design Review
CRITICAL 9.8 PyPI

PaddlePaddle vulnerable to Code Injection

GHSA-gcjf-29m9-888q · CVE-2022-46742 · PYSEC-2022-43063

Published · Modified

Description

Code injection in paddle.audio.functional.get_window in PaddlePaddle 2.4.0-rc0 allows arbitrary code execution. A patch is available on the develop branch of the repository and anticipated to be part of a 2.4 release.

Ready to move

Start Securing

Free, no credit card | First findings in minutes