CVE-2026-28500Disclosure(linuxfoundation / onnx)

LOWCVSS 9.1 · CRITICAL

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch linuxfoundation onnx systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

Open Neural Network Exchange (ONNX) is an open standard for machine learning interoperability. In versions up to and including 1.20.1, a security control bypass exists in onnx.hub.load() due to improper logic in the repository trust verification mechanism. While the function is designed to warn users when loading models from non-official sources, the use of the silent=True parameter completely suppresses all security warnings and confirmation prompts. This vulnerability transforms a standard model-loading function into a vector for Zero-Interaction Supply-Chain Attacks. When chained with file-system vulnerabilities, an attacker can silently exfiltrate sensitive files (SSH keys, cloud credentials) from the victim's machine the moment the model is loaded. As of time of publication, no known patched versions are available.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-345CWE-494CWE-693CWE-829

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • onnx

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 8 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 6 signals
  • Disclosure: 6 classified signals
  • General: 1 classified signal
  • Peaked 3d ago at 4 mentions (2026-03-18); latest day: 1
  • 8 total mentions across 4 days

Affected systems

Products
onnx

Deep dive

Activity timeline8 mentions / 4d
01234Mentions · 2026-03-18: 4Mentions · 2026-03-21: 2Mentions · 2026-03-22: 1Mentions · 2026-04-05: 1PoC Mentioned / Linked · 2026-04-05: 1Patch / Workaround · 2026-03-21: 2Patch / Workaround · 2026-03-22: 1Technical Details · 2026-03-18: 2Technical Details · 2026-03-21: 2Technical Details · 2026-03-22: 1Technical Details · 2026-04-05: 103-1803-2103-2204-05
Signal classification3 categories
Disclosure
675.0%
General
112.5%
Patch
112.5%
Referenced assets7 URLs
Classification over time
DateTotalLabels
2026-03-184
Disclosure3General1
2026-03-212
Disclosure2
2026-03-221
Patch1
2026-04-051
Disclosure1
Full discourse8 posts
  • /r/netsec@_r_netsec
    Disclosure

    ONNX Hub silent=True suppresses all trust verification, enabling supply chain attacks on ML model loading (CVE-2026-28500, CVSS 9.1, no patch available) https://raxe.ai/labs/advisories/RAXE-2026-039

    Post summary

    The advisory announces CVE-2026-28500, a high‑severity flaw in ONNX Hub that disables trust checks, allowing supply chain attacks, and notes that no patch is currently available; it provides technical details but no PoC or exploit.

    10020609
    32.9K followersView on X
  • Security Harvester@secharvesterx
    Disclosure

    ONNX Hub silent=True suppresses all trust verification, enabling supply chain attacks on ML model loading (CVE-2026-28500, CVSS 9.1, no patch available) https://raxe.ai/labs/advisories/RAXE-2026-039 https://t.co/e1MHPFvBZS

    Post summary

    The advisory discloses CVE-2026-28500, a high‑severity flaw in ONNX Hub that disables trust verification via silent=True, permitting supply‑chain attacks, with no patch currently available.

    0101092
    803 followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🟠 CVE-2026-28500 - High Open Neural Network Exchange (ONNX) is an open standard for machine learning interoperability. In versions up to and including 1.20.1, a security control bypass exists in onnx.hub.load() due ... https://www.thehackerwire.com/vulnerability/CVE-2026-28500/ https://t.co/hNReduycHX

    Post summary

    CVE-2026-28500 is a high‑severity security control bypass in ONNX hub.load() affecting releases up to 1.20.1, with no known exploits, patches, or PoC indicated in the brief.

    0002058
    138 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-28500 Open Neural Network Exchange (ONNX) is an open standard for machine learning interoperability. In versions up to and including 1.20.1, a security control bypass exist… https://www.cve.org/CVERecord?id=CVE-2026-28500

    Post summary

    The text is a brief announcement of a security control bypass in ONNX versions up to 1.20.1, without additional details or actionable information.

    00010108
    56.7K followersView on X
  • PulsePatch.io@pulsepatchio
    Disclosure

    Affected: `ONNX` library. Vulnerability (CVE-2026-28500) allows silent loading of untrusted models via `onnx.hub.load()`, posing a supply-chain risk. Verify model sources. #ONNX #SupplyChainSecurity #InfoSec https://www.pulsepatch.io/posts/cve-2026-28500-onnx-silent-model-loading

    Post summary

    CVEs 2026-28500 discloses a silent model loading flaw in ONNX that poses a supply‑chain risk; while a PoC link is provided, no exploitation or patch is mentioned.

    0000034
    4 followersView on X
  • Secwiser - Cyber Security Insights@Secwiserapp
    Patch

    ONNX Hub CVE-2026-28500: Silent model loading CVE-2026-28500: ONNX hub.load() silent=True bypasses trust verification, enabling silent loading of models from attacker-controlled repos. Affects all versions ≤1.20.1; no patch. SHA256 manifest weakness allows tampering. Mitigations: remove silent=True, pin to onnx/models, audit code, and restrict repo references. Read more: https://raxe.ai/labs/advisories/RAXE-2026-039 Discover the app: https://www.secwiser.com/app #CyberSecurity #MachineLearning #AISecurity #Vulnerabilities #CVE #ModelSecurity #AI #CyberDefense #TechTrends #MLSecurity #Secwiser #AISafety

    Post summary

    The advisory explains CVE-2026-28500, detailing how silent=True bypasses trust verification in ONNX hub.load and recommends mitigations, though no official patch exists.

    0000026
    17 followersView on X
  • CVEarity@CVEarity
    Disclosure

    ⚡ New CVE Alert: CVE-2026-28500 📊 Severity: 8.6 🚨 Risk Level: High 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-28500 #CVE-2026-28500 #CVE #High  #CyberSecurity #InfoSec https://t.co/PbfpeD1bU0

    Post summary

    The tweet announces CVE‑2026‑28500 with a high severity score but provides no technical details, PoC, or patch information.

    0000033
    104 followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2026-28500: HIGH] Security vulnerability in ONNX versions up to 1.20.1 allows bypass of trust verification, enabling potential Zero-Interaction Supply-Chain Attacks during model loading. No patches yet.#cve,CVE-2026-28500,#cybersecurity https://cvefind.com/CVE-2026-28500

    Post summary

    The post announces a high‑severity vulnerability (CVE‑2026‑28500) in ONNX 1.20.1 and earlier that allows bypassing trust verification, enabling potential zero‑interaction supply‑chain attacks; no patches or exploit code are mentioned.

    0000061
    603 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Applinuxfoundationonnx---

Explore more