Code Injection in paddlepaddle
        
  Critical severity
        
          GitHub Reviewed
      
        Published
          Jan 20, 2024 
          to the GitHub Advisory Database
          •
          Updated Jan 29, 2024 
      
  
Description
        Published by the National Vulnerability Database
      Jan 20, 2024 
    
  
        Published to the GitHub Advisory Database
      Jan 20, 2024 
    
  
        Reviewed
      Jan 23, 2024 
    
  
        Last updated
      Jan 29, 2024 
    
  
The vulnerability arises from the way the url parameter is incorporated into the command string without proper validation or sanitization. If the url is constructed from untrusted sources, an attacker could potentially inject malicious commands.
References