Junglewise Threat Intelligence

CVE-2026-49114: ONNX save_external_data symlink-following file write

CVE-2026-49114 · Severity: high · CVSS 7.1 · Published 2026-08-21

Technologies: onnx (PyPI). Vendors: PyPI.

Executive brief

ONNX is a machine learning model format and runtime library used to serialize and load neural network models. The save_external_data function contains a symlink-following vulnerability that allows a local attacker with directory write access to redirect file writes to arbitrary locations (such as SSH keys or application config files), potentially leading to unauthorized access or system compromise.

Technical details

A TOCTOU (time-of-check time-of-use) race condition exists in the save_external_data method in external_data_helper.py. The function checks if an external data file exists using os.path.isfile() and then opens it for writing without the O_NOFOLLOW or O_EXCL flags. An attacker with write access to the target directory can plant a symlink between the check and the open call, causing the victim's write to follow the symlink and overwrite any file the victim has write permissions to (e.g., ~/.ssh/authorized_keys, cron files, or application configs). The vulnerability requires local access and user interaction (loading and saving a model), but enables arbitrary file write as the victim user. Fixed in version 1.21.0.

Affected products

  • ONNX ONNX before 1.21.0

Timeline

  • 2026-08-21: disclosed
  • 2026-08-21: patched: Version 1.21.0

References

Related threats