← Späť na vyhľadávanie CVE

CVE-2026-49114

ONNX

Popis

In ONNX before 1.21.0, the -save_external_data- function builds the external-data file path from the model-s external_data location field and opens it for writing without -O_NOFOLLOW/O_EXCL-, after a non-atomic -os.path.isfile()- check. A local attacker with write access to the directory where a victim serializes external data can deterministically pre-plant a symlink that is being followed, causing the victim-s write to append to any file the victim can write, e.g. ~/.ssh/authorized_keys, cron files, or application configs. Fixed in 1.21.0.

CVSS 7.1EPSS 0.107%Riziko 0.72
Zobraziť zdroj
Zverejnené
2026-08-21 16:17:17
Dotknuté verzie
<1.21.0
Typ
Knižnica
Posledná úprava
2026-08-26 16:52:20
Vektor
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H