Path traversal in onnx - CVE-2026-34446
Published: April 27, 2026
onnx
Detailed vulnerability description
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to improper limitation of a pathname to a restricted directory in onnx.load when processing a crafted model with external data hardlinks. A remote attacker can supply a specially crafted model file to disclose sensitive information.
User interaction is required to load the crafted model.