HIGH 8.8
PYSEC-2025-148
Details
Path Traversal vulnerability in onnx.external_data_helper.save_external_data in ONNX 1.17.0 allows attackers to overwrite arbitrary files by supplying crafted external_data.location paths containing traversal sequences, bypassing intended directory restrictions.
Are you affected?
Enter the version of the package you're using.
Affected packages
PyPI / onnx
Introduced in:
0 No fixed version published yet for onnx (pip). Pin to a known-safe version or switch to an alternative.