← Retour à la recherche de CVE

CVE-2026-49114

ONNX

Description

In ONNX before 1.21.0, the -save_external_data- function builds the external-data file path from the model-s external_data location field and opens it for writing without -O_NOFOLLOW/O_EXCL-, after a non-atomic -os.path.isfile()- check. A local attacker with write access to the directory where a victim serializes external data can deterministically pre-plant a symlink that is being followed, causing the victim-s write to append to any file the victim can write, e.g. ~/.ssh/authorized_keys, cron files, or application configs. Fixed in 1.21.0.

CVSS 7.1EPSS 0.107%Risque 0.72
Voir la source
Publication
2026-08-21 16:17:17
Versions concernées
<1.21.0
Type
Bibliothèque
Dernière modification
2026-08-26 16:52:20
Vecteur
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H