PT-2026-29422 · Onnx · Onnx

Pi3Ch

·

Published

2026-03-31

·

Updated

2026-04-02

·

CVE-2026-27489

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions ONNX versions prior to 1.21.0
Description ONNX contains a path traversal vulnerability via symlink that allows reading arbitrary files outside the model or user-provided directory. The vulnerability exists because the check for symlinks is ineffective, allowing a symlink to point to an arbitrary location on the file system. An attacker could provide a victim with a compressed file containing a malicious ONNX model and a symlink, which, when uncompressed and loaded, could allow the attacker to read sensitive files and environment variables from the host system. This issue is not limited to UNIX systems.
Recommendations Update to ONNX version 1.21.0 or later.

Fix

Relative Path Traversal

Weakness Enumeration

Related Identifiers

CVE-2026-27489
GHSA-3R9X-F23J-GC73

Affected Products

Onnx