id: PYSEC-2026-2239 published: "2026-04-01T18:16:28.287Z" modified: "2026-07-13T05:50:25.616846Z" aliases: - CVE-2026-27489 - GHSA-3r9x-f23j-gc73 details: Open Neural Network Exchange (ONNX) is an open standard for machine learning interoperability. Prior to version 1.21.0, a path traversal vulnerability via symlink allows to read arbitrary files outside model or user-provided directory. This issue has been patched in version 1.21.0. affected: - package: name: onnx ecosystem: PyPI purl: pkg:pypi/onnx ranges: - type: ECOSYSTEM events: - introduced: "0" - fixed: 1.21.0 versions: - "0.1" - "0.2" - 0.2.1 - 1.0.0 - 1.0.1 - 1.1.0 - 1.1.1 - 1.1.2 - 1.10.0 - 1.10.1 - 1.10.2 - 1.11.0 - 1.12.0 - 1.13.0 - 1.13.1 - 1.14.0 - 1.14.1 - 1.15.0 - 1.16.0 - 1.16.1 - 1.16.2 - 1.17.0 - 1.18.0 - 1.19.0 - 1.19.1 - 1.19.1rc1 - 1.2.1 - 1.2.2 - 1.2.3 - 1.20.0 - 1.20.0rc1 - 1.20.0rc2 - 1.20.1 - 1.20.1rc1 - 1.21.0rc1 - 1.21.0rc2 - 1.21.0rc3 - 1.21.0rc4 - 1.3.0 - 1.4.0 - 1.4.1 - 1.5.0 - 1.6.0 - 1.7.0 - 1.8.0 - 1.8.1 - 1.9.0 ecosystem_specific: {} references: - type: WEB url: https://access.redhat.com/security/cve/CVE-2026-27489 - type: WEB url: https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-27489.json - type: ADVISORY url: https://access.redhat.com/errata/RHSA-2026:24977 - type: REPORT url: https://bugzilla.redhat.com/show_bug.cgi?id=2453929 - type: FIX url: https://github.com/onnx/onnx/commit/4755f8053928dce18a61db8fec71b69c74f786cb - type: FIX url: https://github.com/onnx/onnx/security/advisories/GHSA-3r9x-f23j-gc73 severity: - type: CVSS_V3 score: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N