PT-2025-12192 · Onnx+1 · Onnx+1

Published

2025-03-20

·

Updated

2025-03-26

·

CVE-2024-7776

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions onnx/onnx framework version 1.16.1 and earlier
Description A vulnerability in the download model function of the onnx/onnx framework allows for arbitrary file overwrite due to inadequate prevention of path traversal attacks in malicious tar files. This issue can be exploited by an attacker to overwrite files in the user's directory, potentially leading to remote command execution.
Recommendations For onnx/onnx framework version 1.16.1 and earlier, update to a version later than 1.16.1 to resolve the issue. As a temporary workaround, consider disabling the download model function until a patch is available. Restrict access to malicious tar files to minimize the risk of exploitation. Avoid using the download model function with untrusted input until the issue is resolved.

Exploit

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-59201
CVE-2024-7776
GHSA-H36J-8VV3-CJ52
PYSEC-2025-10

Affected Products

Debian
Onnx