Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-3r9x-f23j-gc73 | onnx Vulnerable to Path Traversal via Symlink |
Tue, 07 Apr 2026 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Linuxfoundation
Linuxfoundation onnx |
|
| CPEs | cpe:2.3:a:linuxfoundation:onnx:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Linuxfoundation
Linuxfoundation onnx |
|
| Metrics |
cvssV3_1
|
cvssV3_1
|
Thu, 02 Apr 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Onnx
Onnx onnx |
|
| Vendors & Products |
Onnx
Onnx onnx |
Thu, 02 Apr 2026 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-22 | |
| References |
| |
| Metrics |
threat_severity
|
cvssV3_1
|
Wed, 01 Apr 2026 23:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Open Neural Network Exchange (ONNX) is an open standard for machine learning interoperability. Prior to version 1.21.0, a path traversal vulnerability via symlink allows to read arbitrary files outside model or user-provided directory. This issue has been patched in version 1.21.0. | |
| Title | ONNX: Path Traversal via Symlink | |
| Weaknesses | CWE-23 CWE-61 |
|
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-04-01T19:09:18.474Z
Reserved: 2026-02-19T19:46:03.541Z
Link: CVE-2026-27489
Updated: 2026-04-01T19:09:15.456Z
Status : Analyzed
Published: 2026-04-01T18:16:28.287
Modified: 2026-04-07T20:22:04.480
Link: CVE-2026-27489
OpenCVE Enrichment
Updated: 2026-04-08T19:57:00Z
Github GHSA