Database/AI/ML frameworks & serving
ONNX: Security-control bypass through 1.20.1
CVSS 8.6CVE-2026-28500AI/ML frameworks & servingcurated
Impact
Security-control bypass through 1.20.1
Who can reach it
Customer-supplied ONNX model
What to do
Upgrade; ONNX external-data handling has no durable fix — sandbox model parsing
References
Related entries
- ONNX: Directory traversal via `external_data` field in the tensor protoCVE-2022-25882 · ONNXHigh
- ONNX: Directory traversal in `external_data` — bypass of the 1.13 fixCVE-2024-27318 · ONNXHigh
- ONNX (`ExternalDataInfo`): Security control bypass in external-data path handlingCVE-2026-34445 · ONNX (`ExternalDataInfo`)High
- JupyterLab: saved HTML cell output can run arbitrary JupyterLab commands on one user clickCVE-2026-42557 · JupyterLab (HTML sanitizer / CommandLinker command dispatch)High
- LocalAI (`/models/apply`): Unauthenticated SSRF fetching arbitrary internal URLsCVE-2026-59707 · LocalAI (`/models/apply`)High
- Text Generation Inference (TGI): SSRF in the OpenAI-compatible multimodal chat endpointCVE-2026-63086 · Text Generation Inference (TGI)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.