---
id: CVE-2024-0817
aliases:
  - GHSA-fh54-3vhg-mpc2
  - PYSEC-2026-1754
title: PaddlePaddle command injection vulnerability
summary: PaddlePaddle command injection vulnerability
severity: high
cvss: 7.8
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'
vendor: paddlepaddle
product: paddlepaddle
ecosystem: pip
affected:
  - paddlepaddle <= 2.6.0
published: '2024-03-07'
updated: '2026-09-10'
sourceUpdated: '2026-09-10T03:50:10.451888082Z'
source: OSV
sourceUrl: 'https://osv.dev/vulnerability/GHSA-fh54-3vhg-mpc2'
references:
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2024-0817'
  - url: >-
      https://github.com/PaddlePaddle/Paddle/commit/bdf6234fdc22e6ee7948950d271cbbe1d27edc93
  - url: 'https://github.com/PaddlePaddle/Paddle'
  - url: 'https://huntr.com/bounties/44d5cbd9-a046-417b-a8d4-bea6fda9cbe3'
tags:
  - osv
  - pip
epss: 0.01166
epssPercentile: 0.65968
ingestedAt: '2026-07-08T18:25:48.906Z'
---

## Overview

Command injection in IrGraph.draw in paddlepaddle/paddle 2.6.0

## Affected packages

- `paddlepaddle <= 2.6.0`

## Remediation

Refer to the advisory for the patched release.
