CVE-2022-25882
HIGH 8.7EPSS 1.6%
Versions of the package onnx before 1.13.0 are vulnerable to Directory Traversal as the external_data field of the tensor proto can have a path to the file which is outside the model current directory or user-provided directory, for example "../../../etc/passwd"
- CVSS v4.0
- 8.7 HIGH
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N - CVSS v3.1
- 7.5 HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N - CVSS v3.1
- 7.5 HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N - CVSS v3.1
- 7.5 HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N - EPSS
- 1.61% chance of exploitation in the next 30 days, 74th percentile
- Published
- 2023-01-25
- Updated
- 2025-04-01
Proof-of-concept exploits (3)
- https://gist.github.com/jnovikov/02a9aff9bf2188033e77bd91ff062856
- onnx/onnx/issues/3991
- https://security.snyk.io/vuln/SNYK-PYTHON-ONNX-2395479