Skip to content
ONNXGHSA-whh8-fjgc-qp73

Onnx Directory Traversal vulnerability

High7.5CVE-2024-27318 · Published Feb 23, 2024 · updated Sep 10, 2026

Versions of the package onnx before and including 1.15.0 are vulnerable to Directory Traversal as the external_data field of the tensor proto can have a path to the file which is outside the model current directory or user-provided directory. The vulnerability occurs as a bypass for the patch added for CVE-2022-25882.

GitHub advisory

Affected versions

PackageAffectedFixed in
onnx
PyPI
< 1.16.01.16.0
Details and references

More ONNX advisories

All ONNX
Advisory
onnx Vulnerable to Path Traversal via Symlink
HighMar 31
ONNX: insufficient authenticity check
High8.6Mar 16
Open Neural Network Exchange (ONNX) Path Traversal Vulnerability
High8.1Mar 20, 2025
onnx allows Arbitrary File Overwrite in download_model_with_test_data
High8.8Jun 6, 2024
Onnx Out-of-bounds Read vulnerability
Medium4.4Feb 23, 2024
Directory Traversal in onnx
High7.5Jan 26, 2023

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.