Skip to content
ONNXGHSA-ffxj-547x-5j7c

Directory Traversal in onnx

High7.5CVE-2022-25882 · Published Jan 26, 2023 · updated Apr 1, 2025

Versions of the package onnx before 1.13.0 are vulnerable to Directory Traversal as the external_data field of the tensor proto can have a path to the file which is outside the model current directory or user-provided directory, for example "../../../etc/passwd"

GitHub advisory

Affected versions

PackageAffectedFixed in
onnx
PyPI
< 1.13.01.13.0
Details and references

More ONNX advisories

All ONNX
Advisory
onnx Vulnerable to Path Traversal via Symlink
HighMar 31
ONNX: insufficient authenticity check
High8.6Mar 16
Open Neural Network Exchange (ONNX) Path Traversal Vulnerability
High8.1Mar 20, 2025
onnx allows Arbitrary File Overwrite in download_model_with_test_data
High8.8Jun 6, 2024
Onnx Directory Traversal vulnerability
High7.5Feb 23, 2024
Onnx Out-of-bounds Read vulnerability
Medium4.4Feb 23, 2024

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.