PT-2025-12192 · Onnx+1 · Onnx+1
Published
2025-03-20
·
Updated
2025-03-26
·
CVE-2024-7776
CVSS v3.1
9.1
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
onnx/onnx framework version 1.16.1 and earlier
Description
A vulnerability in the
download model function of the onnx/onnx framework allows for arbitrary file overwrite due to inadequate prevention of path traversal attacks in malicious tar files. This issue can be exploited by an attacker to overwrite files in the user's directory, potentially leading to remote command execution.Recommendations
For onnx/onnx framework version 1.16.1 and earlier, update to a version later than 1.16.1 to resolve the issue. As a temporary workaround, consider disabling the
download model function until a patch is available. Restrict access to malicious tar files to minimize the risk of exploitation. Avoid using the download model function with untrusted input until the issue is resolved.Exploit
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Debian
Onnx