PT-2025-30434 · Microsoft · Onnx

Geckosecurity

·

Published

2024-06-06

·

Updated

2025-12-06

·

CVE-2025-51480

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions ONNX version 1.17.0
Description A path traversal issue exists in the onnx.external data helper.save external data function. This allows attackers to overwrite arbitrary files by providing crafted external data.location paths containing traversal sequences, which bypasses intended directory restrictions.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Path traversal

Weakness Enumeration

Related Identifiers

AZL-65658
AZL-65661
CVE-2025-51480
GHSA-6RQ9-53C3-F7VJ

Affected Products

Onnx