CVE-2026-27489: 
Python vulnerability analysis and mitigation

Overview

CVE-2026-27489 is a path traversal vulnerability via symbolic link (symlink) in the Open Neural Network Exchange (ONNX) library that allows an attacker to read arbitrary files outside the model or user-provided directory. It affects all ONNX versions prior to 1.21.0 (pip package onnx <= 1.20.0). The vulnerability was published on March 31, 2026, and patched in version 1.21.0. It carries a CVSS v3.1 score of 7.5 (High) and a CVSS v4.0 score of 8.7 (High) (GitHub Advisory, Red Hat Bugzilla).

Technical details

The root cause lies in the use of std::filesystem::is_regular_file() in onnx/checker.cc (lines 1024–1033) to validate external data file paths referenced by ONNX models. This function performs a status(p) call that follows symbolic links, so it returns true if the symlink target is a regular file — effectively bypassing the intended symlink check (CWE-61, CWE-23, CWE-22). An attacker crafts a malicious ONNX model whose external data file reference (location field) points to a symlink targeting an arbitrary file on the host filesystem (e.g., /etc/passwd or /proc/1/environ). The attack is not limited to UNIX; Windows systems are also affected, though O_NOFOLLOW protections are unavailable there. A full proof-of-concept is publicly available in the security advisory (GitHub Advisory, ONNX Commit).

Impact

Successful exploitation allows an unauthenticated attacker to read arbitrary files accessible to the ONNX checker process, including sensitive system files (/etc/passwd, /etc/shadow), environment variables (/proc/1/environ), application secrets, and credentials. There is no integrity or availability impact — the vulnerability is purely a confidentiality breach. In ML pipeline or model-serving environments where ONNX models are loaded from untrusted sources, this could expose secrets that enable lateral movement or privilege escalation (GitHub Advisory, Red Hat Bugzilla).

Exploitability

A working proof-of-concept exploit is publicly available in the ONNX security advisory on GitHub, with step-by-step reproduction instructions (GitHub Advisory). The vulnerability requires no authentication, no privileges, and no user interaction beyond the victim loading a malicious model file. There is no evidence of in-the-wild exploitation at this time, and it is not listed in the CISA KEV catalog. The EPSS score is approximately 0.063% (low probability of near-term exploitation), and no threat actor attribution has been reported (GitHub Advisory).

Exploitation steps

  1. Craft a malicious ONNX model: Use the ONNX Python API to create a model with large external tensor data saved to a separate file (e.g., model.onnx + model.data), using onnx.save_model(..., save_as_external_data=True).
  2. Replace the data file with a symlink: Delete the legitimate model.data file and create a symbolic link in its place pointing to the target sensitive file: ln -s /etc/passwd model.data.
  3. Package and deliver: Compress the malicious model.onnx and the model.data symlink into an archive (e.g., .zip or .tar.gz) and deliver it to the victim (e.g., via email, model repository, or supply chain).
  4. Victim loads the model: When the victim extracts the archive and loads the model using onnx.load('model.onnx') or load_external_data_for_model(model, '.'), the ONNX checker's is_regular_file() call follows the symlink, passes validation, and reads the symlink target.
  5. Exfiltrate data: The contents of the targeted file (e.g., /etc/passwd, /proc/1/environ) are loaded into the model's tensor data, which the attacker can then retrieve (GitHub Advisory).

Indicators of compromise

  • File System: Presence of a .data file in an ONNX model directory that is actually a symbolic link (detectable via ls -la or find . -type l); symlinks pointing to sensitive system paths such as /etc/passwd, /etc/shadow, /proc/1/environ, or application credential files.
  • File System: ONNX model archives (.zip, .tar.gz) containing both a .onnx file and a .data symlink — inspect archive contents before extraction.
  • Logs: Application or ML pipeline logs showing unexpected file read errors or unusually large tensor data loaded from system paths; Python tracebacks referencing external_data_helper.py or checker.cc with paths outside the model directory.
  • Process: ONNX loader process (python, onnxruntime) opening files outside the expected model directory, observable via strace -e openat or equivalent system call tracing tools (GitHub Advisory).

Mitigation and workarounds

Upgrade ONNX to version 1.21.0 or later, which implements a four-layer defense-in-depth fix: canonical path containment (std::filesystem::weakly_canonical() in C++, os.path.realpath() in Python), explicit symlink rejection, O_NOFOLLOW on file open (Linux/macOS Python paths), and hardlink count checks (ONNX Commit). Until patching is possible, restrict loading of ONNX models from untrusted or unverified sources, and run the ONNX checker process under a least-privilege account with minimal filesystem access. On Linux, consider using sandboxing (e.g., seccomp, namespaces) to limit the files accessible to the ONNX process (GitHub Advisory, Red Hat Bugzilla).

Community reactions

The vulnerability was reported by researcher pi3ch and published by andife to the ONNX security advisory on March 31, 2026. A technical blog post analyzing the vulnerability and noting incomplete prior fixes was published on dev.to by SecDim shortly after disclosure (GitHub Advisory). Red Hat tracked the issue via Bugzilla and classified it as high severity, indicating downstream impact on Linux distributions shipping ONNX (Red Hat Bugzilla). Tenable released a Nessus detection plugin (ID 304744) within days of the patch.

Additional resources

Linux Distribution fix status

Fix availability across major Linux distributions and their releases.

Debian

Affected

bookworm

onnx

Affected

sid

onnx

Affected

trixie

onnx

Affected

Ubuntu

Affected

devel

onnx

Affected

jammy

onnx

Affected

jammy (esm-apps)

onnx

Affected

noble

onnx

Affected

noble (esm-apps)

onnx

Affected

resolute

onnx

Affected

resolute (esm-apps)

onnx

Affected

RHEL / CentOS

Unknown

Source: This report was generated using AI

Related Python vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

GHSA-v2f8-6655-7grjCRITICAL10
  • Python logoPython
  • vibe-trading-ai
NoYesOct 02, 2026
CVE-2026-105782HIGH7.5
  • Python logoPython
  • scrapy
NoYesOct 06, 2026
GHSA-v853-p72q-4cfwHIGH7.5
  • Python logoPython
  • quart
NoYesOct 05, 2026
CVE-2026-105751MEDIUM6.9
  • Python logoPython
  • docling
NoYesOct 05, 2026
CVE-2026-105750MEDIUM5.9
  • Python logoPython
  • docling
NoYesOct 05, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management