Home » Database

AVID-2026-R1360

Description

Vulnerability CVE-2024-0818

Details

Arbitrary File Overwrite Via Path Traversal in paddlepaddle/paddle before 2.6

Reason for inclusion in AVID: CVE-2024-0818 describes a path traversal vulnerability in paddlepaddle/paddle prior to 2.6 that allows arbitrary file overwrites. PaddlePaddle is a widely used AI framework for training and deploying AI models, placing this as an issue in the AI software stack. The vulnerability directly affects software components used to build/run general-purpose AI systems (dependencies/runtime in AI pipelines), and its CVSS indicates a high-severity security impact (high integrity/availability impact, network-based exploitation with no user interaction). The report provides explicit vulnerability details and references, sufficient to classify as a software supply chain vulnerability in AI systems.

References

Affected or Relevant Artifacts

  • Developer: paddlepaddle
  • Deployer: paddlepaddle
  • Artifact Details:
TypeName
Systempaddlepaddle/paddle

Impact

AVID Taxonomy Categorization

  • Risk domains: Security
  • SEP subcategories: S0100: Software Vulnerability
  • Lifecycle stages: L06: Deployment

CVSS

Version3.0
Vector StringCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
Base Score9.1
Base Severity🔴 Critical
Attack VectorNETWORK
Attack Complexity🟢 Low
Privileges RequiredNONE
User InteractionNONE
ScopeUNCHANGED
Confidentiality ImpactNONE
Integrity Impact🔴 High
Availability Impact🔴 High

CWE

IDDescription
CWE-22CWE-22 Improper Limitation of a Pathname to a Restricted Directory (‘Path Traversal’)

Other information

  • Report Type: Advisory
  • Credits:
  • Date Reported: 2024-03-07
  • Version: 0.3.3
  • AVID Entry