CVE-2026-27489Disclosure(linuxfoundation / onnx)

LOWCVSS 7.5 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch linuxfoundation onnx systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Open Neural Network Exchange (ONNX) is an open standard for machine learning interoperability. Prior to version 1.21.0, a path traversal vulnerability via symlink allows to read arbitrary files outside model or user-provided directory. This issue has been patched in version 1.21.0.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-23CWE-61CWE-22

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • onnx

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 4 signals
  • Disclosure: 3 classified signals
  • Peaked 1d ago at 2 mentions (2026-04-01); latest day: 2
  • 4 total mentions across 2 days

Affected systems

Products
onnx

Deep dive

Activity timeline4 mentions / 2d
01122Mentions · 2026-04-01: 2Mentions · 2026-04-02: 2Patch / Workaround · 2026-04-01: 2Technical Details · 2026-04-01: 2Technical Details · 2026-04-02: 204-0104-02
Signal classification2 categories
Disclosure
375.0%
Patch
125.0%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-04-012
Disclosure1Patch1
2026-04-022
Disclosure2
Full discourse4 posts
  • White Rabbitx 🏴‍☠️@TheRabbitPy
    Patch

    🌊 CVE-2026-27489 (onnx): High path traversal via symlink—arbitrary file access. Patch: ONNX latest https://www.tenable.com/cve/newest https://nvd.nist.gov/vuln/detail/CVE-2026-27489 https://github.com/onnx/onnx/security/advisories

    Post summary

    CVE‑2026‑27489 enables path traversal via symlinks in ONNX, permitting arbitrary file access, and a patch is available in the latest ONNX release.

    1002010
    1.4K followersView on X
  • SecDim@secdim
    Disclosure

    We found a zero-day path traversal in ONNX — CVE-2026-27489. It took three patches to get fixed. We break down how the vulnerability survived each fix and what it takes to actually kill a traversal bug. 👉 Full analysis: https://secdim.com/blog/post/two-incomplete-fixes-for-a-path-traversal-vulnerability-in-onnx-cve-2026-27489-18075/ #appsec #securecoding #onnx https://t.co/1mgKWVlKlQ

    Post summary

    The post discloses a zero‑day path traversal (CVE‑2026‑27489) in ONNX, summarizes that three patches were issued, and provides analysis of the vulnerability’s persistence and mitigation. It serves as a detailed disclosure rather than implying active exploitation.

    00110182
    280 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-27489 Open Neural Network Exchange (ONNX) is an open standard for machine learning interoperability. Prior to version 1.21.0, a path traversal vulnerability via symlink all… https://www.cve.org/CVERecord?id=CVE-2026-27489

    Post summary

    The post announces a path‑traversal vulnerability in ONNX prior to version 1.21.0, with no PoC, exploit, or patch details provided.

    00010323
    56.9K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-27489 Open Neural Network Exchange (ONNX) is an open standard for machine learning interoperability. Prior to version 1.21.0, a path traversal vulnerability via symlink all… https://www.cve.org/CVERecord?id=CVE-2026-27489 ----- Traducción: CVE-2026-27489 Ope… http://infoflow.cloud`

    Post summary

    The post announces CVE-2026-27489, a path traversal flaw in ONNX before version 1.21.0, linking to the CVE record but providing no PoC, exploit, patch, or evidence of active exploitation.

    0000045
    65 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Applinuxfoundationonnx---

Explore more