CVE-2024-7776

CRITICAL

onnx <= 1.16.1 - Path Traversal and Arbitrary File Overwrite via Malicious Tar File

Title source: llm
STIX 2.1

Description

A vulnerability in the `download_model` function of the onnx/onnx framework, before and including version 1.16.1, allows for arbitrary file overwrite due to inadequate prevention of path traversal attacks in malicious tar files. This vulnerability can be exploited by an attacker to overwrite files in the user's directory, potentially leading to remote command execution.

References (1)

Core 1
Core References

Scores

CVSS v3 9.1
EPSS 0.0526
EPSS Percentile 90.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

CWE
CWE-22
Status published
Products (2)
onnx/onnx < 1.16.1
pypi/onnx 0 - 1.17.0PyPI
Published Mar 20, 2025
Tracked Since Feb 18, 2026