VDB
KO

PYSEC-2023-38

Details

Versions of the package onnx before 1.13.0 are vulnerable to Directory Traversal as the external_data field of the tensor proto can have a path to the file which is outside the model current directory or user-provided directory, for example "../../../etc/passwd"

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI / onnx
Introduced in: 0 Fixed in: f369b0e859024095d721f1d1612da5a8fa38988d
Fix pip install --upgrade 'onnx>=f369b0e859024095d721f1d1612da5a8fa38988d'

References