{"data":{"ecosystem":"pypi","name":"onnx","url":"https://aisecwatch.com/packages/pypi/onnx","latestVersion":"1.23.2","firstReleaseAt":"2017-09-07T07:46:59.342Z","repository":"https://github.com/onnx/onnx","llm":{"exposure":"none","depth":null,"integratedAt":null,"integratedVersion":null,"sdks":[],"path":[]},"authority":{"profile":[],"fromDependencies":[]},"dependencies":[{"ecosystem":"pypi","name":"ml-dtypes","versionSpec":">=0.5.4","scope":"runtime"},{"ecosystem":"pypi","name":"numpy","versionSpec":">=1.23.2","scope":"runtime"},{"ecosystem":"pypi","name":"pillow","versionSpec":">=12.2.0","scope":"extra:reference"},{"ecosystem":"pypi","name":"protobuf","versionSpec":">=6.31.1","scope":"runtime"},{"ecosystem":"pypi","name":"typing-extensions","versionSpec":">=4.7.1","scope":"runtime"}],"advisories":[{"id":"e4ade73a-d44b-417e-b2bb-dfeca6d9adec","url":"https://aisecwatch.com/issues/e4ade73a-d44b-417e-b2bb-dfeca6d9adec","cveId":"CVE-2026-49114","title":"CVE-2026-49114: In ONNX before 1.21.0, the 'save_external_data' function builds the external-data file path from the model's…","headline":"ONNX symlink following in save_external_data allows arbitrary file writes","severity":"high","publishedAt":"2026-08-21T16:17:17.863Z","affected":["onnx@<= 1.20.1 (fixed: 1.21.0)"],"epssScore":0.00159,"matchedBy":"ecosystem"},{"id":"fae4e0f3-3bfd-4f0e-a6a4-158f6d684b47","url":"https://aisecwatch.com/issues/fae4e0f3-3bfd-4f0e-a6a4-158f6d684b47","cveId":"CVE-2026-63632","title":"CVE-2026-63632: Open Neural Network Exchange (ONNX) is an open standard for machine learning interoperability. From 1.3.0 until 1.22.0…","headline":"ONNX version converter out-of-bounds read in Gemm opset 7 to 6 downgrade","severity":"low","publishedAt":"2026-08-18T15:16:56.463Z","affected":["onnx@>= 1.3.0, <= 1.21.0 (fixed: 1.22.0)"],"epssScore":0.00168,"matchedBy":"ecosystem"},{"id":"87c7523e-461c-47af-b4c0-30d8e18ee07e","url":"https://aisecwatch.com/issues/87c7523e-461c-47af-b4c0-30d8e18ee07e","cveId":"CVE-2026-44512","title":"GHSA-hwpq-hmq9-wj77: ONNX has Null Pointer Dereference in Upsample Version Converter Adapter (Zero Inputs)","headline":null,"severity":"medium","publishedAt":"2026-07-07T13:02:10.000Z","affected":["onnx@>= 1.9.0, < 1.22.0 (fixed: 1.22.0)"],"epssScore":0.00193,"matchedBy":"ecosystem"},{"id":"d12e8bcd-5f76-4373-8bcf-2c1190d22f51","url":"https://aisecwatch.com/issues/d12e8bcd-5f76-4373-8bcf-2c1190d22f51","cveId":null,"title":"GHSA-q56x-g2fj-4rj6: ONNX: TOCTOU arbitrary file read/write in save_external_dat ","headline":null,"severity":"high","publishedAt":"2026-04-01T23:40:58.000Z","affected":["onnx@<= 1.20.1 (fixed: 1.21.0)"],"epssScore":null,"matchedBy":"ecosystem"},{"id":"c3407137-eabb-4f17-849d-2b0d35798050","url":"https://aisecwatch.com/issues/c3407137-eabb-4f17-849d-2b0d35798050","cveId":"CVE-2026-34447","title":"CVE-2026-34447: Open Neural Network Exchange (ONNX) is an open standard for machine learning interoperability. Prior to version 1.21.0…","headline":"ONNX symlink traversal reads files outside model directory","severity":"medium","publishedAt":"2026-04-01T18:16:30.810Z","affected":["onnx@< 1.21.0 (fixed: 1.21.0)"],"epssScore":0.00191,"matchedBy":"ecosystem"},{"id":"37b2d237-1810-4fa3-bf69-1ba00974bde6","url":"https://aisecwatch.com/issues/37b2d237-1810-4fa3-bf69-1ba00974bde6","cveId":"CVE-2026-34446","title":"CVE-2026-34446: Open Neural Network Exchange (ONNX) is an open standard for machine learning interoperability. Prior to version 1.21.0…","headline":"ONNX path traversal in onnx.load through hardlinks","severity":"medium","publishedAt":"2026-04-01T18:16:30.660Z","affected":["onnx@<= 1.20.1 (fixed: 1.21.0)"],"epssScore":0.00171,"matchedBy":"ecosystem"},{"id":"c7d2d94e-5db1-418d-84a9-753d64644562","url":"https://aisecwatch.com/issues/c7d2d94e-5db1-418d-84a9-753d64644562","cveId":"CVE-2026-34445","title":"CVE-2026-34445: Open Neural Network Exchange (ONNX) is an open standard for machine learning interoperability. Prior to version 1.21.0…","headline":"ONNX ExternalDataInfo unsafe attribute setting from model metadata","severity":"high","publishedAt":"2026-04-01T18:16:30.500Z","affected":["onnx@<= 1.20.1 (fixed: 1.21.0)"],"epssScore":0.00506,"matchedBy":"ecosystem"},{"id":"866d04e4-d573-4b74-9b4a-71f430fa4cae","url":"https://aisecwatch.com/issues/866d04e4-d573-4b74-9b4a-71f430fa4cae","cveId":"CVE-2026-27489","title":"CVE-2026-27489: Open Neural Network Exchange (ONNX) is an open standard for machine learning interoperability. Prior to version 1.21.0…","headline":"Open Neural Network Exchange path traversal via symlink to read arbitrary files","severity":"high","publishedAt":"2026-04-01T18:16:28.287Z","affected":["onnx@<= 1.20.0 (fixed: 1.21.0)"],"epssScore":0.00616,"matchedBy":"ecosystem"},{"id":"b7cf06eb-9a84-4f39-a8b9-744a21505d3b","url":"https://aisecwatch.com/issues/b7cf06eb-9a84-4f39-a8b9-744a21505d3b","cveId":"CVE-2026-28500","title":"GHSA-hqmj-h5c6-369m: ONNX Untrusted Model Repository Warnings Suppressed by silent=True in onnx.hub.load() — Silent Supply-Chain Attack","headline":null,"severity":"high","publishedAt":"2026-03-16T16:23:28.000Z","affected":["onnx@<= 1.20.1"],"epssScore":0.00312,"matchedBy":"ecosystem"},{"id":"6387b784-7763-4f32-97cd-cd1650bd1555","url":"https://aisecwatch.com/issues/6387b784-7763-4f32-97cd-cd1650bd1555","cveId":"CVE-2024-7776","title":"CVE-2024-7776: A vulnerability in the `download_model` function of the onnx/onnx framework, before and including version 1.16.1…","headline":"onnx download_model arbitrary file overwrite via path traversal in tar files","severity":"critical","publishedAt":"2025-03-20T14:15:37.520Z","affected":["onnx@< 1.17.0 (fixed: 1.17.0)"],"epssScore":0.01519,"matchedBy":"ecosystem"},{"id":"9bb91717-2c07-43af-a7b6-6d6e33809bcc","url":"https://aisecwatch.com/issues/9bb91717-2c07-43af-a7b6-6d6e33809bcc","cveId":"CVE-2024-5187","title":"CVE-2024-5187: A vulnerability in the `download_model_with_test_data` function of the onnx/onnx framework, version 1.16.0, allows for…","headline":"onnx/onnx arbitrary file overwrite via path traversal in tar extraction","severity":"high","publishedAt":"2024-06-06T23:16:06.100Z","affected":["onnx@< 1.16.2 (fixed: 1.16.2)"],"epssScore":0.01178,"matchedBy":"ecosystem"},{"id":"6c00f971-4d19-46cf-8c70-2f9d2b679dfc","url":"https://aisecwatch.com/issues/6c00f971-4d19-46cf-8c70-2f9d2b679dfc","cveId":"CVE-2024-27319","title":"CVE-2024-27319: Versions of the package onnx before and including 1.15.0 are vulnerable to Out-of-bounds Read as the ONNX_ASSERT and…","headline":"onnx out-of-bounds read in ONNX_ASSERT and ONNX_ASSERTM string copy","severity":"medium","publishedAt":"2024-02-23T23:15:50.960Z","affected":["onnx@<= 1.15.0 (fixed: 1.16.0)"],"epssScore":0.00589,"matchedBy":"ecosystem"},{"id":"ea8a8df2-c362-4e61-9df6-57f1c231e845","url":"https://aisecwatch.com/issues/ea8a8df2-c362-4e61-9df6-57f1c231e845","cveId":"CVE-2024-27318","title":"CVE-2024-27318: Versions of the package onnx before and including 1.15.0 are vulnerable to Directory Traversal as the external_data…","headline":"onnx directory traversal through the external_data field of tensor proto","severity":"high","publishedAt":"2024-02-23T23:15:50.767Z","affected":["onnx@<= 1.15.0 (fixed: 1.16.0)"],"epssScore":0.01179,"matchedBy":"ecosystem"},{"id":"6cbc35db-84c5-4fb5-b8c1-b46076b9d03b","url":"https://aisecwatch.com/issues/6cbc35db-84c5-4fb5-b8c1-b46076b9d03b","cveId":"CVE-2022-25882","title":"CVE-2022-25882: Versions of the package onnx before 1.13.0 are vulnerable to Directory Traversal as the external_data field of the…","headline":"onnx directory traversal through the external_data field of tensor proto","severity":"high","publishedAt":"2023-01-27T02:15:31.333Z","affected":["onnx@< 1.13.0 (fixed: 1.13.0)"],"epssScore":0.01608,"matchedBy":"ecosystem"}],"checkedAt":"2026-10-09T21:54:28.691Z"},"meta":{"advisoryMatching":"by package name and ecosystem; an advisory with no ecosystem recorded for the package is matched by name alone"}}