onnxruntime is vulnerable to Path Traversal
58
Medium Risk
Affected versions of this package allow external data references in TensorProto to point to arbitrary file locations without enforcing that the data resides under the model directory, enabling unsafe path resolution. An attacker could craft a malicious model containing absolute paths or path traversal sequences (e.g., ../) to force the system to load unintended files from the host filesystem. This may result in unauthorized file access, sensitive data disclosure, or unintended behavior depending on the execution environment. Exploitation typically requires supplying a specially crafted model that bypasses directory validation during external data loading.
You are affected if you are using a version that falls within the vulnerable range.
onnxruntime is vulnerable to Path Traversal in versions 1.21.0 - 1.24.0.
Upgrade the onnxruntime library to the patch version.
Secure your code, cloud, and runtime environments in one central system. Find and fix vulnerabilities automatically.
No credit card required | Scan results in 32secs.
SOC 2Compliant
ISO 27001Compliant