Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-6946 | A vulnerability in the `download_model` function of the onnx/onnx framework, before and including version 1.16.1, allows for arbitrary file overwrite due to inadequate prevention of path traversal attacks in malicious tar files. This vulnerability can be exploited by an attacker to overwrite files in the user's directory, potentially leading to remote command execution. |
Github GHSA |
GHSA-h36j-8vv3-cj52 | Open Neural Network Exchange (ONNX) Path Traversal Vulnerability |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Wed, 26 Mar 2025 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Onnx
Onnx onnx |
|
| CPEs | cpe:2.3:a:onnx:onnx:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Onnx
Onnx onnx |
|
| Metrics |
cvssV3_1
|
Thu, 20 Mar 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 20 Mar 2025 10:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability in the `download_model` function of the onnx/onnx framework, before and including version 1.16.1, allows for arbitrary file overwrite due to inadequate prevention of path traversal attacks in malicious tar files. This vulnerability can be exploited by an attacker to overwrite files in the user's directory, potentially leading to remote command execution. | |
| Title | Arbitrary File Overwrite in onnx/onnx | |
| Weaknesses | CWE-22 | |
| References |
| |
| Metrics |
cvssV3_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: @huntr_ai
Published:
Updated: 2025-03-20T15:52:00.491Z
Reserved: 2024-08-13T21:28:43.911Z
Link: CVE-2024-7776
Updated: 2025-03-20T15:51:52.199Z
Status : Analyzed
Published: 2025-03-20T10:15:37.520
Modified: 2025-03-26T17:20:27.680
Link: CVE-2024-7776
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA