
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-27489 is a path traversal vulnerability via symbolic link (symlink) in the Open Neural Network Exchange (ONNX) library that allows an attacker to read arbitrary files outside the model or user-provided directory. It affects all ONNX versions prior to 1.21.0 (pip package onnx <= 1.20.0). The vulnerability was published on March 31, 2026, and patched in version 1.21.0. It carries a CVSS v3.1 score of 7.5 (High) and a CVSS v4.0 score of 8.7 (High) (GitHub Advisory, Red Hat Bugzilla).
The root cause lies in the use of std::filesystem::is_regular_file() in onnx/checker.cc (lines 1024–1033) to validate external data file paths referenced by ONNX models. This function performs a status(p) call that follows symbolic links, so it returns true if the symlink target is a regular file — effectively bypassing the intended symlink check (CWE-61, CWE-23, CWE-22). An attacker crafts a malicious ONNX model whose external data file reference (location field) points to a symlink targeting an arbitrary file on the host filesystem (e.g., /etc/passwd or /proc/1/environ). The attack is not limited to UNIX; Windows systems are also affected, though O_NOFOLLOW protections are unavailable there. A full proof-of-concept is publicly available in the security advisory (GitHub Advisory, ONNX Commit).
Successful exploitation allows an unauthenticated attacker to read arbitrary files accessible to the ONNX checker process, including sensitive system files (/etc/passwd, /etc/shadow), environment variables (/proc/1/environ), application secrets, and credentials. There is no integrity or availability impact — the vulnerability is purely a confidentiality breach. In ML pipeline or model-serving environments where ONNX models are loaded from untrusted sources, this could expose secrets that enable lateral movement or privilege escalation (GitHub Advisory, Red Hat Bugzilla).
A working proof-of-concept exploit is publicly available in the ONNX security advisory on GitHub, with step-by-step reproduction instructions (GitHub Advisory). The vulnerability requires no authentication, no privileges, and no user interaction beyond the victim loading a malicious model file. There is no evidence of in-the-wild exploitation at this time, and it is not listed in the CISA KEV catalog. The EPSS score is approximately 0.063% (low probability of near-term exploitation), and no threat actor attribution has been reported (GitHub Advisory).
model.onnx + model.data), using onnx.save_model(..., save_as_external_data=True).model.data file and create a symbolic link in its place pointing to the target sensitive file: ln -s /etc/passwd model.data.model.onnx and the model.data symlink into an archive (e.g., .zip or .tar.gz) and deliver it to the victim (e.g., via email, model repository, or supply chain).onnx.load('model.onnx') or load_external_data_for_model(model, '.'), the ONNX checker's is_regular_file() call follows the symlink, passes validation, and reads the symlink target./etc/passwd, /proc/1/environ) are loaded into the model's tensor data, which the attacker can then retrieve (GitHub Advisory)..data file in an ONNX model directory that is actually a symbolic link (detectable via ls -la or find . -type l); symlinks pointing to sensitive system paths such as /etc/passwd, /etc/shadow, /proc/1/environ, or application credential files..zip, .tar.gz) containing both a .onnx file and a .data symlink — inspect archive contents before extraction.external_data_helper.py or checker.cc with paths outside the model directory.python, onnxruntime) opening files outside the expected model directory, observable via strace -e openat or equivalent system call tracing tools (GitHub Advisory).Upgrade ONNX to version 1.21.0 or later, which implements a four-layer defense-in-depth fix: canonical path containment (std::filesystem::weakly_canonical() in C++, os.path.realpath() in Python), explicit symlink rejection, O_NOFOLLOW on file open (Linux/macOS Python paths), and hardlink count checks (ONNX Commit). Until patching is possible, restrict loading of ONNX models from untrusted or unverified sources, and run the ONNX checker process under a least-privilege account with minimal filesystem access. On Linux, consider using sandboxing (e.g., seccomp, namespaces) to limit the files accessible to the ONNX process (GitHub Advisory, Red Hat Bugzilla).
The vulnerability was reported by researcher pi3ch and published by andife to the ONNX security advisory on March 31, 2026. A technical blog post analyzing the vulnerability and noting incomplete prior fixes was published on dev.to by SecDim shortly after disclosure (GitHub Advisory). Red Hat tracked the issue via Bugzilla and classified it as high severity, indicating downstream impact on Linux distributions shipping ONNX (Red Hat Bugzilla). Tenable released a Nessus detection plugin (ID 304744) within days of the patch.
Fix availability across major Linux distributions and their releases.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."