VDB
KO
HIGH 8.8

PYSEC-2025-148

Details

Path Traversal vulnerability in onnx.external_data_helper.save_external_data in ONNX 1.17.0 allows attackers to overwrite arbitrary files by supplying crafted external_data.location paths containing traversal sequences, bypassing intended directory restrictions.

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI / onnx
Introduced in: 0

No fixed version published yet for onnx (pip). Pin to a known-safe version or switch to an alternative.

References