{"apiVersion":"1.0","identifier":"CVE-2026-49114","description":"In ONNX before 1.21.0, the -save_external_data- function builds the external-data file path from the model-s external_data location field and opens it for writing without -O_NOFOLLOW/O_EXCL-, after a non-atomic -os.path.isfile()- check. A local attacker with write access to the directory where a victim serializes external data can deterministically pre-plant a symlink that is being followed, causing the victim-s write to append to any file the victim can write, e.g. ~/.ssh/authorized_keys, cron files, or application configs. Fixed in 1.21.0.","publishedAt":"2026-08-21T16:17:17","lastModifiedAt":"2026-08-26T16:52:20","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-49114","cvssScore":7.1,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H","epssProbability":0.00107,"riskScore":0.72,"affectedProduct":"ONNX","affectedVersions":"<1.21.0","vulnerabilityType":"Library","operatingSystems":[],"links":{"self":"https://www.redsauce.net/api/cves/CVE-2026-49114","webPages":{"es":"https://www.redsauce.net/es/cves/CVE-2026-49114","en":"https://www.redsauce.net/en/cves/CVE-2026-49114","fr":"https://www.redsauce.net/fr/cves/CVE-2026-49114","pt":"https://www.redsauce.net/pt/cves/CVE-2026-49114","de":"https://www.redsauce.net/de/cves/CVE-2026-49114","sk":"https://www.redsauce.net/sk/cves/CVE-2026-49114","el":"https://www.redsauce.net/el/cves/CVE-2026-49114"},"source":"https://nvd.nist.gov/vuln/detail/CVE-2026-49114"}}