CVE-2024-7776 is a critical path traversal vulnerability in the onnx/onnx framework, specifically within the download_model function, affecting versions up to and including 1.16.1. This flaw allows an unauthenticated attacker to overwrite arbitrary files on a user's system by providing a specially crafted malicious tar file, potentially leading to remote command execution. With a CVSS score of 9.1 (CRITICAL) and a FAUCET Risk Score of 85/100, the vulnerability is easily exploitable over the network with low attack complexity and no user interaction required, posing a significant risk to integrity and availability. While no public exploit code, Metasploit modules, or active exploitation have been observed, and community discussion is minimal, the high severity warrants immediate patching.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 1.16.1CPE matchmatch criteria | cpe:2.3:a:onnx:onnx:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Third-Party Package Updates in Python for Scientific Computing - June 2025
Jun 12, 2025Open Neural Network Exchange (ONNX) Path Traversal Vulnerability
Mar 20, 2025Arbitrary File Overwrite in onnx/onnx
Mar 11, 2025