VDB
Sign up
—

PYSEC-2023-38

Quick fix

PYSEC-2023-38 — onnx: upgrade to the fixed version with the command below.

pip install --upgrade 'onnx>=f369b0e859024095d721f1d1612da5a8fa38988d'

Details

Versions of the package onnx before 1.13.0 are vulnerable to Directory Traversal as the external_data field of the tensor proto can have a path to the file which is outside the model current directory or user-provided directory, for example "../../../etc/passwd"

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI/onnx
Introduced in: 0Fixed in: f369b0e859024095d721f1d1612da5a8fa38988d
Fixpip install --upgrade 'onnx>=f369b0e859024095d721f1d1612da5a8fa38988d'

References