Skip to content
ONNXGHSA-6rq9-53c3-f7vj

onnx allows Arbitrary File Overwrite in download_model_with_test_data

High8.8CVE-2024-5187 · Published Jun 6, 2024 · updated Jun 6, 2026

A vulnerability in the `download_model_with_test_data` function of the onnx/onnx framework, versions before 1.16.2, allow for arbitrary file overwrite due to inadequate prevention of path traversal attacks in malicious tar files. This vulnerability enables attackers to overwrite any file on the system, potentially leading to remote code execution, deletion of system, personal, or application files, thus impacting the integrity and availability of the system. The issue arises from the function's handling of tar file extraction without performing security checks on the paths within the tar file, as demonstrated by the ability to overwrite the `/home/kali/.ssh/authorized_keys` file by specifying an absolute path in the malicious tar file.

GitHub advisory

Affected versions

PackageAffectedFixed in
onnx
PyPI
< 1.16.21.16.2
Details and references

More ONNX advisories

All ONNX
Advisory
onnx Vulnerable to Path Traversal via Symlink
HighMar 31
ONNX: insufficient authenticity check
High8.6Mar 16
Open Neural Network Exchange (ONNX) Path Traversal Vulnerability
High8.1Mar 20, 2025
Onnx Out-of-bounds Read vulnerability
Medium4.4Feb 23, 2024
Onnx Directory Traversal vulnerability
High7.5Feb 23, 2024
Directory Traversal in onnx
High7.5Jan 26, 2023

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.