Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2024-7776

25
FAUCET Score

CVE-2024-7776 is a critical path traversal vulnerability in the onnx/onnx framework, specifically within the download_model function, affecting versions up to and including 1.16.1. This flaw allows an unauthenticated attacker to overwrite arbitrary files on a user's system by providing a specially crafted malicious tar file, potentially leading to remote command execution. With a CVSS score of 9.1 (CRITICAL) and a FAUCET Risk Score of 85/100, the vulnerability is easily exploitable over the network with low attack complexity and no user interaction required, posing a significant risk to integrity and availability. While no public exploit code, Metasploit modules, or active exploitation have been observed, and community discussion is minimal, the high severity warrants immediate patching.

Impacted Technologies

VendorProductVersion(s)CPE
<= 1.16.1CPE matchmatch criteria
cpe:2.3:a:onnx:onnx:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.0

8.1HIGH

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
2.8
Impact Score
5.2
CvssVersion
3.0

Exploit Intelligence

EPSS Score
1.36%
Probability of exploitation in next 30 days
EPSS Percentile
68.8%
Percentile rank of EPSS score among Peer Group
As of 2026-07-24
Model: v2026.06.15
This CVE's current EPSS score of 0.0136 is in the 55th percentile among its peer group of 36,829 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (6)

esetpatch availablevia llm_extracted
Fixed in: 4.2.3
View patch
microsoftpatch availablevia msrc
Product: 17466-17084Fixed in: 2.2.2-5
microsoftpatch availablevia msrc
Product: 19407-17084Fixed in: 2.2.2-5
microsoftpatch availablevia msrc
Product: azl3 pytorch 2.2.2-5 on Azure Linux 3.0Fixed in: 2.2.2-5
microsoftpatch availablevia msrc
Product: azl3 pytorch 2.2.2-7 on Azure Linux 3.0Fixed in: 2.2.2-5
pippatch availablevia ghsa
Product: onnxFixed in: 1.17.0

Vendor Advisories (3)

esetllm-eset-633ddbad236cf4deCRITICAL

Third-Party Package Updates in Python for Scientific Computing - June 2025

Jun 12, 2025
pipGHSA-h36j-8vv3-cj52high

Open Neural Network Exchange (ONNX) Path Traversal Vulnerability

Mar 20, 2025
microsoft2025-Mar/CVE-2024-7776Important

Arbitrary File Overwrite in onnx/onnx

Mar 11, 2025

References

huntr.com / bounties/a7a46cf6-1fa0-454b-988c-62d222e83f63
ExploitThird Party Advisory