
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-34447 is a symlink traversal vulnerability in the Open Neural Network Exchange (ONNX) library's external data loading mechanism that allows arbitrary file reads outside the intended model directory. It affects all ONNX versions prior to 1.21.0 (pip package) and was published on March 31, 2026, with NVD analysis completed April 1, 2026. The vulnerability carries a CVSS v3.1 base score of 5.5 (Medium) (GitHub Advisory, ONNX Security Advisory).
The root cause lies in the resolve_external_data_location() function in onnx/onnx/checker.cc (lines 970–1060), classified under CWE-22 (Path Traversal) and CWE-61 (UNIX Symlink Following). The function correctly rejects empty paths, absolute paths, and .. sequences, and normalizes the relative path before constructing data_path = base_dir / relative_path. However, it validates the result using std::filesystem::is_regular_file(data_path), which transparently follows symbolic links to their targets — meaning a symlink placed inside base_dir that points to a file outside base_dir passes all checks. The resolved path is then returned and opened by the Python loader via external_data_helper.load_external_data_for_tensor, resulting in the contents of the out-of-bounds file being read into the model's tensor raw_data (ONNX Security Advisory).
Successful exploitation results in a high-confidentiality-impact, arbitrary file read: any file accessible to the process loading the ONNX model can be exfiltrated, including sensitive system files such as /etc/passwd, private keys, or application credentials. There is no integrity or availability impact. The attack is local in vector and requires user interaction (a user or automated pipeline must load the crafted model), but no privileges are required, making it particularly relevant in ML pipeline and model-sharing scenarios where untrusted model files may be ingested (GitHub Advisory, ONNX Security Advisory).
A public proof-of-concept Python script (onnx_external_data_symlink_traversal_poc.py) is available in the GitHub security advisory, demonstrating the vulnerability by creating a symlink to /etc/hosts and confirming arbitrary file read via load_external_data_for_model(). The EPSS score is approximately 0.006% (0th percentile), indicating low near-term exploitation probability. There is no evidence of in-the-wild exploitation or CISA KEV catalog inclusion as of the report date. The vulnerability is detected by Qualys (plugin ID 6635624) and Tenable Nessus (plugin 304715) (ONNX Security Advisory, GitHub Advisory).
tensor.bin) using set_external_data(tensor, location='tensor.bin').tensor.bin inside the model's base directory (base_dir) that points to a target file outside the directory, such as /etc/passwd or /etc/hosts (e.g., pathlib.Path('base_dir/tensor.bin').symlink_to('/etc/passwd')).load_external_data_for_model(model, base_dir=model_dir), which invokes resolve_external_data_location() in checker.cc. The function validates the path, follows the symlink (via std::filesystem::is_regular_file()), and returns the resolved path.tensor.raw_data. The attacker retrieves the tensor data from the loaded model object, obtaining the contents of the out-of-bounds file (ONNX Security Advisory)..bin or other tensor data extensions) inside ONNX model directories pointing to files outside the model directory (e.g., /etc/passwd, /etc/hosts, private key files); unexpected .onnx model files received from external sources in ML pipeline input directories.load_external_data_for_model() calls on models from untrusted or external sources; Python tracebacks or unusual tensor data sizes inconsistent with model architecture./etc/passwd, /etc/hosts) outside the expected model data directory, observable via strace/auditd file access logs.Upgrade ONNX to version 1.21.0 or later, which contains the fix for this vulnerability (GitHub Advisory). As interim workarounds: implement filesystem-level controls (e.g., nofollow mount options or AppArmor/SELinux policies) to prevent symlink creation or following within model directories; restrict permissions on directories used for external model data loading; and when processing untrusted ONNX models, sandbox the loading process or use a restricted filesystem namespace (e.g., Linux namespaces/chroot) that limits accessible files to only those required by the model (ONNX Security Advisory).
Fix availability across major Linux distributions and their releases.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."