CVE-2026-34447: 
Python vulnerability analysis and mitigation

Overview

CVE-2026-34447 is a symlink traversal vulnerability in the Open Neural Network Exchange (ONNX) library's external data loading mechanism that allows arbitrary file reads outside the intended model directory. It affects all ONNX versions prior to 1.21.0 (pip package) and was published on March 31, 2026, with NVD analysis completed April 1, 2026. The vulnerability carries a CVSS v3.1 base score of 5.5 (Medium) (GitHub Advisory, ONNX Security Advisory).

Technical details

The root cause lies in the resolve_external_data_location() function in onnx/onnx/checker.cc (lines 970–1060), classified under CWE-22 (Path Traversal) and CWE-61 (UNIX Symlink Following). The function correctly rejects empty paths, absolute paths, and .. sequences, and normalizes the relative path before constructing data_path = base_dir / relative_path. However, it validates the result using std::filesystem::is_regular_file(data_path), which transparently follows symbolic links to their targets — meaning a symlink placed inside base_dir that points to a file outside base_dir passes all checks. The resolved path is then returned and opened by the Python loader via external_data_helper.load_external_data_for_tensor, resulting in the contents of the out-of-bounds file being read into the model's tensor raw_data (ONNX Security Advisory).

Impact

Successful exploitation results in a high-confidentiality-impact, arbitrary file read: any file accessible to the process loading the ONNX model can be exfiltrated, including sensitive system files such as /etc/passwd, private keys, or application credentials. There is no integrity or availability impact. The attack is local in vector and requires user interaction (a user or automated pipeline must load the crafted model), but no privileges are required, making it particularly relevant in ML pipeline and model-sharing scenarios where untrusted model files may be ingested (GitHub Advisory, ONNX Security Advisory).

Exploitability

A public proof-of-concept Python script (onnx_external_data_symlink_traversal_poc.py) is available in the GitHub security advisory, demonstrating the vulnerability by creating a symlink to /etc/hosts and confirming arbitrary file read via load_external_data_for_model(). The EPSS score is approximately 0.006% (0th percentile), indicating low near-term exploitation probability. There is no evidence of in-the-wild exploitation or CISA KEV catalog inclusion as of the report date. The vulnerability is detected by Qualys (plugin ID 6635624) and Tenable Nessus (plugin 304715) (ONNX Security Advisory, GitHub Advisory).

Exploitation steps

  1. Craft a malicious ONNX model: Create an ONNX model file that references an external tensor data file by a relative path (e.g., tensor.bin) using set_external_data(tensor, location='tensor.bin').
  2. Create a symlink in the model directory: Place a symbolic link named tensor.bin inside the model's base directory (base_dir) that points to a target file outside the directory, such as /etc/passwd or /etc/hosts (e.g., pathlib.Path('base_dir/tensor.bin').symlink_to('/etc/passwd')).
  3. Deliver the model to the victim: Package the model file and the symlink together (e.g., in a zip or tar archive that preserves symlinks) and distribute it to a target who will load it with ONNX.
  4. Trigger model loading: The victim (or an automated ML pipeline) calls load_external_data_for_model(model, base_dir=model_dir), which invokes resolve_external_data_location() in checker.cc. The function validates the path, follows the symlink (via std::filesystem::is_regular_file()), and returns the resolved path.
  5. Exfiltrate file contents: The Python loader reads the symlink target file into tensor.raw_data. The attacker retrieves the tensor data from the loaded model object, obtaining the contents of the out-of-bounds file (ONNX Security Advisory).

Indicators of compromise

  • File System: Presence of symbolic links (.bin or other tensor data extensions) inside ONNX model directories pointing to files outside the model directory (e.g., /etc/passwd, /etc/hosts, private key files); unexpected .onnx model files received from external sources in ML pipeline input directories.
  • Logs: Application or pipeline logs showing load_external_data_for_model() calls on models from untrusted or external sources; Python tracebacks or unusual tensor data sizes inconsistent with model architecture.
  • Process: Python processes loading ONNX models that subsequently access system files (e.g., /etc/passwd, /etc/hosts) outside the expected model data directory, observable via strace/auditd file access logs.
  • Network: Exfiltration of file contents following model loading in networked ML inference services; unexpected outbound data transfers correlated with model ingestion events (ONNX Security Advisory).

Mitigation and workarounds

Upgrade ONNX to version 1.21.0 or later, which contains the fix for this vulnerability (GitHub Advisory). As interim workarounds: implement filesystem-level controls (e.g., nofollow mount options or AppArmor/SELinux policies) to prevent symlink creation or following within model directories; restrict permissions on directories used for external model data loading; and when processing untrusted ONNX models, sandbox the loading process or use a restricted filesystem namespace (e.g., Linux namespaces/chroot) that limits accessible files to only those required by the model (ONNX Security Advisory).

Additional resources

Linux Distribution fix status

Fix availability across major Linux distributions and their releases.

Debian

Affected

bookworm

onnx

Affected

sid

onnx

Affected

trixie

onnx

Affected

Ubuntu

Affected

devel

onnx

Affected

jammy

onnx

Affected

jammy (esm-apps)

onnx

Affected

noble

onnx

Affected

noble (esm-apps)

onnx

Affected

resolute

onnx

Affected

resolute (esm-apps)

onnx

Affected

Source: This report was generated using AI

Related Python vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

GHSA-v2f8-6655-7grjCRITICAL10
  • Python logoPython
  • vibe-trading-ai
NoYesOct 02, 2026
CVE-2026-105782HIGH7.5
  • Python logoPython
  • scrapy
NoYesOct 06, 2026
GHSA-v853-p72q-4cfwHIGH7.5
  • Python logoPython
  • quart
NoYesOct 05, 2026
CVE-2026-105751MEDIUM6.9
  • Python logoPython
  • docling
NoYesOct 05, 2026
CVE-2026-105750MEDIUM5.9
  • Python logoPython
  • docling
NoYesOct 05, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management