---
id: CVE-2024-0818
aliases:
  - GHSA-2rp8-hff9-c5wr
  - PYSEC-2026-442
title: PaddlePaddle Path Traversal vulnerability
summary: PaddlePaddle Path Traversal vulnerability
severity: critical
cvss: 9.1
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H'
vendor: paddlepaddle
product: paddlepaddle
ecosystem: pip
affected:
  - paddlepaddle <= 2.6.0
published: '2024-03-07'
updated: '2026-09-10'
sourceUpdated: '2026-09-10T03:50:00.238928928Z'
source: OSV
sourceUrl: 'https://osv.dev/vulnerability/GHSA-2rp8-hff9-c5wr'
references:
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2024-0818'
  - url: >-
      https://github.com/PaddlePaddle/Paddle/commit/5c50d1a8b97b310cbc36560ec36d8377d6f29d7c
  - url: 'https://github.com/PaddlePaddle/Paddle'
  - url: 'https://huntr.com/bounties/85b06a1b-ac0b-4096-a06d-330891570cd9'
tags:
  - osv
  - pip
epss: 0.01057
epssPercentile: 0.63036
ingestedAt: '2026-09-12T03:13:01.640Z'
---

## Overview

Arbitrary File Overwrite Via Path Traversal in paddlepaddle/paddle before 2.6

## Affected packages

- `paddlepaddle <= 2.6.0`

## Remediation

Refer to the advisory for the patched release.
