CVE-2026-34447
- EPSS 0.01%
- Veröffentlicht 01.04.2026 17:39:38
- Zuletzt bearbeitet 15.04.2026 14:45:48
Open Neural Network Exchange (ONNX) is an open standard for machine learning interoperability. Prior to version 1.21.0, there is a symlink traversal vulnerability in external data loading allows reading files outside the model directory. This issue h...
CVE-2026-34446
- EPSS 0.01%
- Veröffentlicht 01.04.2026 17:37:54
- Zuletzt bearbeitet 15.04.2026 15:03:15
Open Neural Network Exchange (ONNX) is an open standard for machine learning interoperability. Prior to version 1.21.0, there is an issue in onnx.load, the code checks for symlinks to prevent path traversal, but completely misses hardlinks because a ...
CVE-2026-27489
- EPSS 0.07%
- Veröffentlicht 01.04.2026 17:33:51
- Zuletzt bearbeitet 07.04.2026 20:22:04
Open Neural Network Exchange (ONNX) is an open standard for machine learning interoperability. Prior to version 1.21.0, a path traversal vulnerability via symlink allows to read arbitrary files outside model or user-provided directory. This issue has...
CVE-2026-34445
- EPSS 0.06%
- Veröffentlicht 01.04.2026 17:30:19
- Zuletzt bearbeitet 15.04.2026 15:08:13
Open Neural Network Exchange (ONNX) is an open standard for machine learning interoperability. Prior to version 1.21.0, the ExternalDataInfo class in ONNX was using Python’s setattr() function to load metadata (like file paths or data lengths) direct...
CVE-2026-28500
- EPSS 0.01%
- Veröffentlicht 18.03.2026 01:15:07
- Zuletzt bearbeitet 18.03.2026 19:47:59
Open Neural Network Exchange (ONNX) is an open standard for machine learning interoperability. In versions up to and including 1.20.1, a security control bypass exists in onnx.hub.load() due to improper logic in the repository trust verification mech...
CVE-2025-51480
- EPSS 0.11%
- Veröffentlicht 22.07.2025 00:00:00
- Zuletzt bearbeitet 08.10.2025 13:11:30
Path Traversal vulnerability in onnx.external_data_helper.save_external_data in ONNX 1.17.0 allows attackers to overwrite arbitrary files by supplying crafted external_data.location paths containing traversal sequences, bypassing intended directory r...
CVE-2024-7776
- EPSS 1.47%
- Veröffentlicht 20.03.2025 10:10:58
- Zuletzt bearbeitet 26.03.2025 17:20:27
A vulnerability in the `download_model` function of the onnx/onnx framework, before and including version 1.16.1, allows for arbitrary file overwrite due to inadequate prevention of path traversal attacks in malicious tar files. This vulnerability ca...