PT-2026-29422 · Onnx · Onnx

·

CVE-2026-27489

·

Published

2026-03-31

·

Updated

2026-04-02

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions ONNX versions prior to 1.21.0
Description ONNX contains a path traversal vulnerability via symlink that allows reading arbitrary files outside the model or user-provided directory. The vulnerability exists because the check for symlinks is ineffective, allowing a symlink to point to an arbitrary location on the file system. An attacker could provide a victim with a compressed file containing a malicious ONNX model and a symlink, which, when uncompressed and loaded, could allow the attacker to read sensitive files and environment variables from the host system. This issue is not limited to UNIX systems.
Recommendations Update to ONNX version 1.21.0 or later.

Exploit

Fix

Relative Path Traversal

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-27489
ECHO-BBDD-CC38-C3A7
GHSA-3R9X-F23J-GC73
PYSEC-2026-2239

Affected Products

Onnx