Open Neural Network Exchange (ONNX) is an open standard for machine learning interoperability. Prior to version 1.21.0, a path traversal vulnerability via symlink allows to read arbitrary files outside model or user-provided directory. This issue has been patched in version 1.21.0.
{
"cwe_ids": [
"CWE-23",
"CWE-61"
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/27xxx/CVE-2026-27489.json",
"cna_assigner": "GitHub_M"
}{
"cpe": "cpe:2.3:a:linuxfoundation:onnx:*:*:*:*:*:*:*:*",
"source": [
"CPE_RANGE",
"REFERENCES"
],
"extracted_events": [
{
"introduced": "0"
},
{
"fixed": "1.21.0"
}
]
}"2026-07-22T03:45:06Z"
[
{
"signature_type": "Function",
"target": {
"file": "onnx/test/cpp/checker_test.cc",
"function": "TEST"
},
"deprecated": false,
"source": "https://github.com/onnx/onnx/commit/4755f8053928dce18a61db8fec71b69c74f786cb",
"id": "CVE-2026-27489-1c13077d",
"signature_version": "v1",
"digest": {
"function_hash": "171595224107432415865451095612645417277",
"length": 594.0
}
},
{
"signature_type": "Line",
"target": {
"file": "onnx/checker.cc"
},
"deprecated": false,
"source": "https://github.com/onnx/onnx/commit/4755f8053928dce18a61db8fec71b69c74f786cb",
"id": "CVE-2026-27489-4429487e",
"signature_version": "v1",
"digest": {
"line_hashes": [
"228678263053640163634378299783059359750",
"323833544844054158561062823797021038285",
"225032623827825878554203818684697560664",
"218707300894504106333349360406091060021"
],
"threshold": 0.9
}
},
{
"signature_type": "Line",
"target": {
"file": "onnx/test/cpp/checker_test.cc"
},
"deprecated": false,
"source": "https://github.com/onnx/onnx/commit/4755f8053928dce18a61db8fec71b69c74f786cb",
"id": "CVE-2026-27489-56a69e83",
"signature_version": "v1",
"digest": {
"line_hashes": [
"218288394427601728521351396430827211120",
"42432593148723861583193071788987341782",
"336236154891539408442439795233444959315",
"291290094037961951241678697160067183433",
"331398135653175476328052973631614322333",
"118516037992418821336602591496477483044",
"194781643396134294354155936686240613805",
"44958690227046309347923048194384148717",
"300265392542811807704877275921678215621",
"105033630908411330797904335496737241560",
"160260508019604022187775333275064325983",
"83992370454356990473768534046789826673",
"238941290079941163367183133488752298007",
"286507889305868357548744830176196086354",
"99287519628577725525674265252450334298",
"2396405549788145168914682694727490067",
"84524617042980626330252108547642044072",
"181313589861014950882572946727086481850",
"32187197892255643856615512722887910669",
"239789386876594353884571210992664706067",
"138641820875017571778594800564050929436"
],
"threshold": 0.9
}
},
{
"signature_type": "Function",
"target": {
"file": "onnx/checker.cc",
"function": "resolve_external_data_location"
},
"deprecated": false,
"source": "https://github.com/onnx/onnx/commit/4755f8053928dce18a61db8fec71b69c74f786cb",
"id": "CVE-2026-27489-740779f7",
"signature_version": "v1",
"digest": {
"function_hash": "93534487257072582615783703272541332060",
"length": 1940.0
}
}
]
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-27489.json"