<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T02:20:47.363881+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cve-2026-27489</id>
    <title>CVE-2026-27489 — ONNX: Path Traversal via Symlink</title>
    <updated>2026-10-03T02:20:47.365718+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> onnx, Red Hat OpenShift AI 2.25, Red Hat OpenShift AI (RHOAI)</p>
<p>Open Neural Network Exchange (ONNX) is an open standard for machine learning interoperability. Prior to version 1.21.0, a path traversal vulnerability via symlink allows to read arbitrary files outside model or user-provided directory. This issue has been patched in version 1.21.0.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cve-2026-27489"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-3r9x-f23j-gc73</id>
    <title>GHSA-3r9x-f23j-gc73 — onnx Vulnerable to Path Traversal via Symlink</title>
    <updated>2026-10-03T02:20:47.365779+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: onnx</p>
<p>### Summary
A path traversal vulnerability via symlink allows to read arbitrary files outside model or user-provided directory.</p>
<p>### Details
The following check for symlink is ineffective and it is possible to point a symlink to an arbitrary location on the file system:
https://github.com/onnx/onnx/blob/336652a4b2ab1e530ae02269efa7038082cef250/onnx/checker.cc#L1024-L1033</p>
<p>`std::filesystem::is_regular_file` performs a `status(p)` call on the provided path, which follows symbolic links to determine the file type, meaning it will return true if the target of a symlink is a regular file.</p>
<p>### PoC</p>
<p>```python
# Create a demo model with external data
import os
import numpy as np
import onnx
from onnx import helper, TensorProto, numpy_helper</p>
<p>def create_onnx_model(output_path="model.onnx"):
    weight_matrix = np.random.randn(1000, 1000).astype(np.float32)</p>
<p>X = helper.make_tensor_value_info("X", TensorProto.FLOAT, [1, 1000])
    Y = helper.make_tensor_value_info("Y", TensorProto.FLOAT, [1, 1000])
    W = numpy_helper.from_array(weight_matrix, name="W")</p>
<p>matmul_node = helper.make_node("MatMul", inputs=["X", "W"], outputs=["Y"], name="matmul")</p>
<p>graph = helper.make_graph(
        nodes=[matmul_node],
        name="SimpleModel",
        inputs=[X],
        outputs=[Y],
        initializer=[W]
    )</p>
<p>model = helper.make_model(graph, opset_imports=[helper.make_opsetid("", 11)])
    onnx.checker.check_model(model)</p>
<p>data_file = output_path.replace('.onnx', '.data')…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-3r9x-f23j-gc73"/>
  </entry>
</feed>
