Impact
Tract is a lightweight, self‑contained TensorFlow and ONNX inference toolkit. In versions before 0.21.17, 0.22.3, and 0.23.2, the tract‑onnx crate accepts an attacker‑controlled external_data location from an ONNX model and incorporates it into the model path without rejecting absolute paths or parent directory components. When an untrusted model is loaded via model_for_path, onnx/src/data_resolver.rs MmapDataResolver can open an arbitrary local file and inject its contents into model tensors or inference output. Attack‑controlled offset and length fields may also choose an out‑of‑range mapping slice, leading to denial of service. The flaw does not permit writing files or executing code. The issue is fixed in the mentioned releases.
Affected Systems
This vulnerability affects the tract library provided by Sonos, specifically the tract‑onnx crate. Versions prior to 0.21.17, 0.22.3, and 0.23.2 are vulnerable. Systems that use tract‑onnx to load ONNX models from untrusted sources are at risk. Applications such as services that invoke tract‑onnx to perform machine‑learning inference on arbitrary user‑provided models must ensure they are running a patched version.
Risk and Exploitability
The CVSS score of 6.1 indicates moderate severity. The EPSS score is < 1%, and the vulnerability is not listed in the CISA KEV catalog, suggesting no documented exploitation yet. However, the path‑traversal weakness (CWE‑22) is widely exploitable when the application runs with sufficient file‑read privileges. An attacker who supplies a malicious ONNX model can read any file the process owns, potentially leaking sensitive data, and may also trigger service disruption via out‑of‑range mappings. The exploit requires only model loading; no additional network access or privilege escalation is needed beyond the existing runtime context.
OpenCVE Enrichment
Github GHSA