CVE-2026-34446 identifies a path traversal vulnerability in Open Neural Network Exchange (ONNX) versions prior to 1.21.0, specifically within the `onnx.load` function, which incorrectly handles hardlinks and could allow access to arbitrary files. Rated as Medium severity with a CVSS score of 4.7, exploitation requires local access and user interaction, but could result in high confidentiality impact through sensitive file disclosure. Currently, there is no evidence of active exploitation, public exploit code, or significant community attention, with its EPSS score indicating a very low probability of exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.21.0CPE matchmatch criteria | cpe:2.3:a:linuxfoundation:onnx:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.