Command injection in IrGraph.draw in paddlepaddle/paddle 2.6.0
The product constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component.
Link | Tags |
---|---|
https://huntr.com/bounties/44d5cbd9-a046-417b-a8d4-bea6fda9cbe3 | third party advisory exploit |