Database/AI/ML frameworks & serving
ONNX: Directory traversal in `external_data` — bypass of the 1.13 fix
CVSS 7.5CVE-2024-27318AI/ML frameworks & servingcurated
Impact
Directory traversal in external_data — bypass of the 1.13 fix
Who can reach it
Customer-supplied ONNX model
What to do
Upgrade past 1.15.0
References
Related entries
- ONNX: Security-control bypass through 1.20.1CVE-2026-28500 · ONNXHigh
- ONNX: Directory traversal via `external_data` field in the tensor protoCVE-2022-25882 · ONNXHigh
- joblib (`NumpyArrayWrapper.read_array`): Deserialization vulnerability in joblib 1.4.2CVE-2024-34997 · joblib (`NumpyArrayWrapper.read_array`)High
- Jupyter Server (Windows): Unauthenticated attackers can leak the NTLM hash of the hostCVE-2024-35178 · Jupyter Server (Windows)High
- Ollama: File-existence disclosure via `api/create`CVE-2024-39719 · OllamaHigh
- Ollama: Path traversal in `api/push` discloses server filesystem layoutCVE-2024-39722 · OllamaHigh
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.