CVE-2025-51480
published 2025-07-22CVE-2025-51480: Path Traversal vulnerability in onnx.external_data_helper.save_external_data in ONNX 1.17.0 allows attackers to overwrite arbitrary files by supplying crafted…
PriorityP347high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
EPSS
0.58%
44.3th percentile
Path Traversal vulnerability in onnx.external_data_helper.save_external_data in ONNX 1.17.0 allows attackers to overwrite arbitrary files by supplying crafted external_data.location paths containing traversal sequences, bypassing intended directory restrictions.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| linuxfoundation | onnx | — | — |
| msrc | azl3_pytorch_2.2.2-10_on_azure_linux_3.0 | — | — |
| msrc | azl3_pytorch_2.2.2-11_on_azure_linux_3.0 | — | — |
| msrc | azl3_pytorch_2.2.2-12_on_azure_linux_3.0 | — | — |
| msrc | azl3_pytorch_2.2.2-7_on_azure_linux_3.0 | — | — |
| msrc | azl3_pytorch_2.2.2-9_on_azure_linux_3.0 | — | — |
| msrc | cbl2_pytorch_2.0.0-11_on_cbl_mariner_2.0 | — | — |
| msrc | cbl2_pytorch_2.0.0-12_on_cbl_mariner_2.0 | — | — |
| msrc | cbl2_pytorch_2.0.0-14_on_cbl_mariner_2.0 | — | — |
| msrc | cbl2_pytorch_2.0.0-15_on_cbl_mariner_2.0 | — | — |
| msrc | cbl2_pytorch_2.0.0-9_on_cbl_mariner_2.0 | — | — |
| onnx | onnx | >= 0 < 1.16.2 | 1.16.2 |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
osv8.8HIGH
vendor_msrc8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-wj32-g77g-8289: Path Traversal vulnerability in onnx
ghsa_unreviewed·2025-07-22
CVE-2025-51480 [HIGH] CWE-22 GHSA-wj32-g77g-8289: Path Traversal vulnerability in onnx
Path Traversal vulnerability in onnx.external_data_helper.save_external_data in ONNX 1.17.0 allows attackers to overwrite arbitrary files by supplying crafted external_data.location paths containing traversal sequences, bypassing intended directory restrictions.
OSV
CVE-2025-51480: Path Traversal vulnerability in onnx
osv·2025-07-22·CVSS 8.8
CVE-2025-51480 [HIGH] CVE-2025-51480: Path Traversal vulnerability in onnx
Path Traversal vulnerability in onnx.external_data_helper.save_external_data in ONNX 1.17.0 allows attackers to overwrite arbitrary files by supplying crafted external_data.location paths containing traversal sequences, bypassing intended directory restrictions.
OSV
onnx allows Arbitrary File Overwrite in download_model_with_test_data
osv·2024-06-06
CVE-2024-5187 [HIGH] onnx allows Arbitrary File Overwrite in download_model_with_test_data
onnx allows Arbitrary File Overwrite in download_model_with_test_data
A vulnerability in the `download_model_with_test_data` function of the onnx/onnx framework, versions before 1.16.2, allow for arbitrary file overwrite due to inadequate prevention of path traversal attacks in malicious tar files. This vulnerability enables attackers to overwrite any file on the system, potentially leading to remote code execution, deletion of system, personal, or application files, thus impacting the integrity and availability of the system. The issue arises from the function's handling of tar file extraction without performing security checks on the paths within the tar file, as demonstrated by the ability to overwrite the `/home/kali/.ssh/authorized_keys` file by specifying an absolute path in the mal
Microsoft
Path Traversal vulnerability in onnx.external_data_helper.save_external_data in ONNX 1.17.0 allows attackers to overwrite arbitrary files by supplying crafted external_data.location paths containing t
vendor_msrc·2025-07-08·CVSS 8.8
CVE-2025-51480 [HIGH] CWE-22 Path Traversal vulnerability in onnx.external_data_helper.save_external_data in ONNX 1.17.0 allows attackers to overwrite arbitrary files by supplying crafted external_data.location paths containing t
Path Traversal vulnerability in onnx.external_data_helper.save_external_data in ONNX 1.17.0 allows attackers to overwrite arbitrary files by supplying crafted external_data.location paths containing traversal sequences, bypassing intended directory restrictions.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If i
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2025-51480 onnx: ONNX path traversal [fedora-42]
bugzilla·2025-07-22·CVSS 8.8
CVE-2025-51480 [HIGH] CVE-2025-51480 onnx: ONNX path traversal [fedora-42]
CVE-2025-51480 onnx: ONNX path traversal [fedora-42]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The following link provides references to all essential vulnerability management information. If something is wrong or missing, please contact a member of PSIRT.
https://spaces.redhat.com/display/PRODSEC/Vulnerability+Management+-+Essential+Documents+for+Engineering+Teams
Discussion:
This comment was flagged as spam, view the edit history to see the original text if required.
---
This message is a reminder that Fedora Linux 42 is nearing its end of life.
Fedora will stop maintaining and issuing updates for Fedor
Bugzilla
CVE-2025-51480 onnxruntime: ONNX path traversal [fedora-42]
bugzilla·2025-07-22·CVSS 8.8
CVE-2025-51480 [HIGH] CVE-2025-51480 onnxruntime: ONNX path traversal [fedora-42]
CVE-2025-51480 onnxruntime: ONNX path traversal [fedora-42]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The following link provides references to all essential vulnerability management information. If something is wrong or missing, please contact a member of PSIRT.
https://spaces.redhat.com/display/PRODSEC/Vulnerability+Management+-+Essential+Documents+for+Engineering+Teams
Discussion:
This message is a reminder that Fedora Linux 42 is nearing its end of life.
Fedora will stop maintaining and issuing updates for Fedora Linux 42 on 2026-05-13.
It is Fedora's policy to close all bug reports from releases that a
2025-07-22
Published