onnx is vulnerable to Path Traversal
85
High Risk
Affected versions of the package allow path traversal attacks when a user tries to download test data from a malicious repository. A tarball in a third-party repository can be downloaded and extracted without proper sanitization, potentially leading to arbitrary file overwriting.
You are affected if you are using a version that falls within the vulnerable range.
onnx is vulnerable to Path Traversal in versions 1.14.0 - 1.16.1.
Upgrade the onnx library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant