CVE-2026-27489 identifies a path traversal vulnerability via symlink in Open Neural Network Exchange (ONNX) versions prior to 1.21.0, allowing attackers to read arbitrary files outside designated directories; this issue has been patched in version 1.21.0. With a CVSSv4 score of 8.7 HIGH, it presents a network attack vector with low complexity and no required privileges or user interaction, leading to a high confidentiality impact. There is currently no evidence of active exploitation (KEV: No), nor are public exploit codes available, and community attention remains minimal with only one recorded mention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.21.0CPE matchmatch criteria | cpe:2.3:a:linuxfoundation:onnx:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.