Arbitrary Attribute Overwrite in Open Neural Network Exchange (ONNX)
CVE-2026-34445
8.6HIGH
What is CVE-2026-34445?
The ExternalDataInfo class in Open Neural Network Exchange (ONNX) enabled loading of metadata directly from ONNX model files without validating the 'keys' present. This oversight allowed attackers to craft malicious models capable of overwriting internal object properties, potentially compromising the integrity of machine learning applications. This vulnerability has been addressed in version 1.21.0, which enhances metadata handling to prevent such arbitrary attribute overwrites.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
onnx < 1.21.0
