Path Traversal Vulnerability in ONNX Product by Open Neural Network Exchange
CVE-2026-34446

4.7MEDIUM

Key Information:

Vendor

Onnx

Status
Vendor
CVE Published:
1 April 2026

What is CVE-2026-34446?

The Open Neural Network Exchange (ONNX) framework, an essential tool for machine learning interoperability, has a vulnerability affecting its loading function. Prior to version 1.21.0, the onnx.load method fails to adequately handle hardlinks, which could be exploited for path traversal attacks. This oversight allows malicious users to access unauthorized files on the system. The issue has been addressed in version 1.21.0, which includes improved checks for both symlinks and hardlinks, enhancing overall security for users.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

onnx < 1.21.0

References

CVSS V3.1

Score:
4.7
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.