Description
Tract is a tiny, no-nonsense, self-contained TensorFlow and ONNX inference toolkit. Prior to 0.21.17, 0.22.3, and 0.23.2, the tract-onnx crate passes the attacker-controlled external_data location from an ONNX model through onnx/src/tensor.rs get_external_resources and joins the value to the model directory without rejecting absolute paths or parent directory components. Loading an untrusted model through model_for_path can therefore make onnx/src/data_resolver.rs MmapDataResolver open an arbitrary local file and place the file contents into model tensors or inference output. Attacker-controlled offset and length fields can also select an out-of-range mapping slice and cause a denial of service, but the flaw does not write files or execute code. This issue is fixed in versions 0.21.17, 0.22.3, and 0.23.2.
Published: 2026-09-14
Score: 6.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Arbitrary Local File Read
Action: Patch Immediately
AI Analysis

Impact

Tract is a lightweight, self‑contained TensorFlow and ONNX inference toolkit. In versions before 0.21.17, 0.22.3, and 0.23.2, the tract‑onnx crate accepts an attacker‑controlled external_data location from an ONNX model and incorporates it into the model path without rejecting absolute paths or parent directory components. When an untrusted model is loaded via model_for_path, onnx/src/data_resolver.rs MmapDataResolver can open an arbitrary local file and inject its contents into model tensors or inference output. Attack‑controlled offset and length fields may also choose an out‑of‑range mapping slice, leading to denial of service. The flaw does not permit writing files or executing code. The issue is fixed in the mentioned releases.

Affected Systems

This vulnerability affects the tract library provided by Sonos, specifically the tract‑onnx crate. Versions prior to 0.21.17, 0.22.3, and 0.23.2 are vulnerable. Systems that use tract‑onnx to load ONNX models from untrusted sources are at risk. Applications such as services that invoke tract‑onnx to perform machine‑learning inference on arbitrary user‑provided models must ensure they are running a patched version.

Risk and Exploitability

The CVSS score of 6.1 indicates moderate severity. The EPSS score is < 1%, and the vulnerability is not listed in the CISA KEV catalog, suggesting no documented exploitation yet. However, the path‑traversal weakness (CWE‑22) is widely exploitable when the application runs with sufficient file‑read privileges. An attacker who supplies a malicious ONNX model can read any file the process owns, potentially leaking sensitive data, and may also trigger service disruption via out‑of‑range mappings. The exploit requires only model loading; no additional network access or privilege escalation is needed beyond the existing runtime context.

Generated by OpenCVE AI on September 20, 2026 at 22:50 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade tract‑onnx to a patched version, at least 0.21.17, or newer 0.22.3 or 0.23.2, as published in the official releases.
  • Validate or restrict the source of ONNX models; process only models from trusted repositories or signatures.
  • Restrict the filesystem permissions of the process that runs tract, limiting read access to only required directories.
  • Configure tract‑onnx to refuse absolute paths or parent directory components in external_data, or disable external_data usage for untrusted models.

Generated by OpenCVE AI on September 20, 2026 at 22:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-h668-6x6g-f8r5 tract: Arbitrary file read via unsanitized ONNX external_data `location` (path traversal) on model load in tract-onnx
History

Tue, 15 Sep 2026 06:00:00 +0000

Type Values Removed Values Added
First Time appeared Sonos
Sonos tract
Vendors & Products Sonos
Sonos tract

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description Tract is a tiny, no-nonsense, self-contained TensorFlow and ONNX inference toolkit. Prior to 0.21.17, 0.22.3, and 0.23.2, the tract-onnx crate passes the attacker-controlled external_data location from an ONNX model through onnx/src/tensor.rs get_external_resources and joins the value to the model directory without rejecting absolute paths or parent directory components. Loading an untrusted model through model_for_path can therefore make onnx/src/data_resolver.rs MmapDataResolver open an arbitrary local file and place the file contents into model tensors or inference output. Attacker-controlled offset and length fields can also select an out-of-range mapping slice and cause a denial of service, but the flaw does not write files or execute code. This issue is fixed in versions 0.21.17, 0.22.3, and 0.23.2.
Title Tract: Arbitrary file read via unsanitized ONNX external_data `location` (path traversal) on model load in tract-onnx
Weaknesses CWE-22
References
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:L'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-14T18:12:59.928Z

Reserved: 2026-06-17T16:29:38.864Z

Link: CVE-2026-55832

cve-icon Vulnrichment

Updated: 2026-09-14T18:12:35.751Z

cve-icon NVD

Status : Deferred

Published: 2026-09-14T18:17:55.663

Modified: 2026-09-30T19:57:08.043

Link: CVE-2026-55832

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T23:00:07Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')