PT-2026-29422 · Onnx · Onnx
Pi3Ch
·
Published
2026-03-31
·
Updated
2026-04-02
·
CVE-2026-27489
CVSS v4.0
8.7
High
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
ONNX versions prior to 1.21.0
Description
ONNX contains a path traversal vulnerability via symlink that allows reading arbitrary files outside the model or user-provided directory. The vulnerability exists because the check for symlinks is ineffective, allowing a symlink to point to an arbitrary location on the file system. An attacker could provide a victim with a compressed file containing a malicious ONNX model and a symlink, which, when uncompressed and loaded, could allow the attacker to read sensitive files and environment variables from the host system. This issue is not limited to UNIX systems.
Recommendations
Update to ONNX version 1.21.0 or later.
Fix
Relative Path Traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Onnx