No analysis available yet.
No remediation available yet.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-6946 | A vulnerability in the `download_model` function of the onnx/onnx framework, before and including version 1.16.1, allows for arbitrary file overwrite due to inadequate prevention of path traversal attacks in malicious tar files. This vulnerability can be exploited by an attacker to overwrite files in the user's directory, potentially leading to remote command execution. |
Github GHSA |
GHSA-h36j-8vv3-cj52 | Open Neural Network Exchange (ONNX) Path Traversal Vulnerability |
Wed, 26 Mar 2025 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Onnx
Onnx onnx |
|
| CPEs | cpe:2.3:a:onnx:onnx:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Onnx
Onnx onnx |
|
| Metrics |
cvssV3_1
|
Thu, 20 Mar 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 20 Mar 2025 10:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability in the `download_model` function of the onnx/onnx framework, before and including version 1.16.1, allows for arbitrary file overwrite due to inadequate prevention of path traversal attacks in malicious tar files. This vulnerability can be exploited by an attacker to overwrite files in the user's directory, potentially leading to remote command execution. | |
| Title | Arbitrary File Overwrite in onnx/onnx | |
| Weaknesses | CWE-22 | |
| References |
| |
| Metrics |
cvssV3_0
|
Status: PUBLISHED
Assigner: @huntr_ai
Published:
Updated: 2025-03-20T15:52:00.491Z
Reserved: 2024-08-13T21:28:43.911Z
Link: CVE-2024-7776
Updated: 2025-03-20T15:51:52.199Z
Status : Analyzed
Published: 2025-03-20T10:15:37.520
Modified: 2025-03-26T17:20:27.680
Link: CVE-2024-7776
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA