affected: - ecosystem_specific: {} package: ecosystem: PyPI name: onnx purl: pkg:pypi/onnx ranges: - events: - introduced: '0' - last_affected: 1.17.0 type: ECOSYSTEM versions: - '0.1' - '0.2' - 0.2.1 - 1.0.0 - 1.0.1 - 1.1.0 - 1.1.1 - 1.1.2 - 1.10.0 - 1.10.1 - 1.10.2 - 1.11.0 - 1.12.0 - 1.13.0 - 1.13.1 - 1.14.0 - 1.14.1 - 1.15.0 - 1.16.0 - 1.16.1 - 1.16.2 - 1.17.0 - 1.2.1 - 1.2.2 - 1.2.3 - 1.3.0 - 1.4.0 - 1.4.1 - 1.5.0 - 1.6.0 - 1.7.0 - 1.8.0 - 1.8.1 - 1.9.0 aliases: - CVE-2025-51480 - GHSA-6rq9-53c3-f7vj details: Path Traversal vulnerability in onnx.external_data_helper.save_external_data in ONNX 1.17.0 allows attackers to overwrite arbitrary files by supplying crafted external_data.location paths containing traversal sequences, bypassing intended directory restrictions. id: PYSEC-2025-148 modified: '2026-05-21T14:54:36.787742Z' published: '2025-07-22T16:15:30.660Z' references: - type: ADVISORY url: https://github.com/advisories/GHSA-6rq9-53c3-f7vj - type: FIX url: https://github.com/onnx/onnx/pull/6959 - type: FIX url: https://github.com/onnx/onnx/pull/7040 - type: PACKAGE url: https://github.com/onnx/onnx - type: EVIDENCE url: https://www.gecko.security/blog/cve-2025-51480 severity: - score: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H type: CVSS_V3