Intel

AIKIDO-2024-10202

onnx is vulnerable to Path Traversal

Path TraversalCVE-2024-5187

85

High Risk

This Affects:

pythononnx
1.14.0 - 1.16.1
Fixed in 1.16.2

TL;DR

Affected versions of the package allow path traversal attacks when a user tries to download test data from a malicious repository. A tarball in a third-party repository can be downloaded and extracted without proper sanitization, potentially leading to arbitrary file overwriting.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

onnx is vulnerable to Path Traversal in versions 1.14.0 - 1.16.1.

How to fix this

Upgrade the onnx library to the patch version.