CVE-2023-38673: Paddlepaddle

Critical severity, CVSS 9.8. EPSS: 2.3% chance of exploitation in the next 30 days.

PaddlePaddle before 2.5.0 has a command injection in fs.py. This resulted in the ability to execute arbitrary commands on the operating system.

Affected products

Published 2023-07-26. Last modified 2026-06-17.