---
id: CVE-2024-0815
aliases:
  - GHSA-qqv2-35q8-p2g2
  - PYSEC-2026-1756
title: 'PaddlePaddle command injection in paddle.utils.download._wget_download '
summary: 'PaddlePaddle command injection in paddle.utils.download._wget_download '
severity: high
cvss: 8.8
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'
vendor: paddlepaddle
product: paddlepaddle
ecosystem: pip
affected:
  - paddlepaddle <= 2.6.0
published: '2024-03-07'
updated: '2026-09-10'
sourceUpdated: '2026-09-10T03:50:10.703916247Z'
source: OSV
sourceUrl: 'https://osv.dev/vulnerability/GHSA-qqv2-35q8-p2g2'
references:
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2024-0815'
  - url: >-
      https://github.com/PaddlePaddle/Paddle/commit/4c0888d7b8f10405e2e79adc41c224264f93e816
  - url: 'https://github.com/PaddlePaddle/Paddle'
  - url: 'https://huntr.com/bounties/83bf8191-b259-4b24-8ec9-0115d7c05350'
tags:
  - osv
  - pip
epss: 0.01132
epssPercentile: 0.65039
ingestedAt: '2026-07-08T18:25:52.472Z'
---

## Overview

Command injection in paddle.utils.download._wget_download (bypass filter) in paddlepaddle/paddle 2.6.0

## Affected packages

- `paddlepaddle <= 2.6.0`

## Remediation

Refer to the advisory for the patched release.
