{"id":"CVE-2024-0815","aliases":["GHSA-qqv2-35q8-p2g2","PYSEC-2026-1756"],"url":"https://o3.security/vulnerability/CVE-2024-0815","summary":"PaddlePaddle command injection in paddle.utils.download._wget_download ","details":"Command injection in paddle.utils.download._wget_download (bypass filter) in paddlepaddle/paddle 2.6.0","published":"2024-03-07T03:13:50.948Z","modified":"2026-08-12T03:51:21.868613886Z","cvss":{"score":9.3,"severity":"CRITICAL","vector":"CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H"},"epss":{"score":0.01132,"percentile":0.6349,"asOf":"2026-08-23"},"cisaKev":null,"exploitsKnown":1,"affectedPackages":[{"ecosystem":"PyPI","name":"paddlepaddle","fixedVersion":null}],"fix":null,"references":[{"type":"WEB","url":"https://huntr.com/bounties/83bf8191-b259-4b24-8ec9-0115d7c05350"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/0xxx/CVE-2024-0815.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-0815"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:21.868613886Z"}}