Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-27489

Опубликовано: 01 апр. 2026
Источник: redhat
CVSS3: 8.6

Описание

Open Neural Network Exchange (ONNX) is an open standard for machine learning interoperability. Prior to version 1.21.0, a path traversal vulnerability via symlink allows to read arbitrary files outside model or user-provided directory. This issue has been patched in version 1.21.0.

A flaw was found in Open Neural Network Exchange (ONNX), an open standard for machine learning interoperability. This path traversal vulnerability, exploitable via a symbolic link (symlink), allows an attacker to read arbitrary files located outside of the intended model or user-provided directories. This could lead to unauthorized information disclosure.

Отчет

This Important flaw in Open Neural Network Exchange (ONNX) affects Red Hat OpenShift AI. An attacker could exploit a path traversal vulnerability through a crafted symbolic link within an ONNX model, leading to unauthorized disclosure of files outside the model's designated directories. This risk is present when processing untrusted ONNX models.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat OpenShift AI (RHOAI)rhoai/odh-openvino-model-server-rhel9Affected
Red Hat OpenShift AI 2.25rhoai/odh-pipeline-runtime-datascience-cpu-py312-rhel9FixedRHSA-2026:2497710.06.2026
Red Hat OpenShift AI 2.25rhoai/odh-pipeline-runtime-pytorch-cuda-py312-rhel9FixedRHSA-2026:2497710.06.2026
Red Hat OpenShift AI 2.25rhoai/odh-pipeline-runtime-pytorch-llmcompressor-cuda-py312-rhel9FixedRHSA-2026:2497710.06.2026
Red Hat OpenShift AI 2.25rhoai/odh-pipeline-runtime-pytorch-rocm-py312-rhel9FixedRHSA-2026:2497710.06.2026
Red Hat OpenShift AI 2.25rhoai/odh-pipeline-runtime-tensorflow-cuda-py312-rhel9FixedRHSA-2026:2497710.06.2026
Red Hat OpenShift AI 2.25rhoai/odh-pipeline-runtime-tensorflow-rocm-py312-rhel9FixedRHSA-2026:2497710.06.2026
Red Hat OpenShift AI 2.25rhoai/odh-workbench-codeserver-datascience-cpu-py312-rhel9FixedRHSA-2026:2497710.06.2026
Red Hat OpenShift AI 2.25rhoai/odh-workbench-jupyter-datascience-cpu-py312-rhel9FixedRHSA-2026:2497710.06.2026
Red Hat OpenShift AI 2.25rhoai/odh-workbench-jupyter-pytorch-cuda-py312-rhel9FixedRHSA-2026:2497710.06.2026

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-22
https://bugzilla.redhat.com/show_bug.cgi?id=2453929onnx: ONNX: Information Disclosure via Path Traversal Vulnerability

8.6 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
5 месяцев назад

Open Neural Network Exchange (ONNX) is an open standard for machine learning interoperability. Prior to version 1.21.0, a path traversal vulnerability via symlink allows to read arbitrary files outside model or user-provided directory. This issue has been patched in version 1.21.0.

CVSS3: 7.5
nvd
5 месяцев назад

Open Neural Network Exchange (ONNX) is an open standard for machine learning interoperability. Prior to version 1.21.0, a path traversal vulnerability via symlink allows to read arbitrary files outside model or user-provided directory. This issue has been patched in version 1.21.0.

CVSS3: 7.5
debian
5 месяцев назад

Open Neural Network Exchange (ONNX) is an open standard for machine le ...

github
5 месяцев назад

onnx Vulnerable to Path Traversal via Symlink

8.6 High

CVSS3