High severity7.5NVD Advisory· Published Feb 23, 2024· Updated Jun 17, 2026
CVE-2024-27318
CVE-2024-27318
Description
Versions of the package onnx before and including 1.15.0 are vulnerable to Directory Traversal as the external_data field of the tensor proto can have a path to the file which is outside the model current directory or user-provided directory. The vulnerability occurs as a bypass for the patch added for CVE-2022-25882.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
onnxPyPI | < 1.16.0 | 1.16.0 |
Affected products
6- ghsa-coords2 versions
< 1.16.0+ 1 more
- (no CPE)range: < 1.16.0
- (no CPE)range: < 1.23.0-r12
cpe:2.3:o:fedoraproject:fedora:39:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:o:fedoraproject:fedora:39:*:*:*:*:*:*:*
- cpe:2.3:o:fedoraproject:fedora:40:*:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
9- github.com/onnx/onnx/commit/66b7fb630903fdcf3e83b6b6d56d82e904264a20nvdPatchWEB
- github.com/advisories/GHSA-whh8-fjgc-qp73ghsaADVISORY
- lists.fedoraproject.org/archives/list/[email protected]/message/FGTBH5ZYL2LGYHIJDHN2MAUURIR5E7PY/nvdThird Party Advisory
- lists.fedoraproject.org/archives/list/[email protected]/message/TFJJID2IZDOLFDMWVYTBDI75ZJQC6JOL/nvdThird Party Advisory
- nvd.nist.gov/vuln/detail/CVE-2024-27318ghsaADVISORY
- github.com/pypa/advisory-database/tree/main/vulns/onnx/PYSEC-2024-222.yamlghsaWEB
- lists.fedoraproject.org/archives/list/[email protected]/message/FGTBH5ZYL2LGYHIJDHN2MAUURIR5E7PYghsaWEB
- lists.fedoraproject.org/archives/list/[email protected]/message/TFJJID2IZDOLFDMWVYTBDI75ZJQC6JOLghsaWEB
- security.snyk.io/vuln/SNYK-PYTHON-ONNX-2395479nvdProductWEB
News mentions
0No linked articles in our index yet.