CVE-2026-108961 | PaddlePaddle PaddleX up to 3.7.2 Preprocessor processors.py NormalizeImage.__init__ scale code injection (Issue 5210)
A vulnerability classified as critical has been found in PaddlePaddle PaddleX up to 3.7.2. Affected by this vulnerability is the function NormalizeImage.__init__ of the file paddlex/inference/models/text_detection/processors.py of the component Preprocessor. This manipulation of the argument scale causes code injection.
The identification of this vulnerability is CVE-2026-108961. It is possible to initiate the attack remotely. There is no exploit available.
The pull request to fix this issue awaits acceptance.VulDB Recent EntriesRead More