Junglewise Threat Intelligence

CVE-2026-55832: Tract is a tiny, no-nonsense, self-contained TensorFlow and ONNX inference toolkit. Prior to 0.21.17, 0.22.3, and 0.23.2, the tract-onnx cra

CVE-2026-55832 · Severity: medium · CVSS 6.1 · Published 2026-09-14

Executive brief

A vulnerability in the tract-onnx library allows a malicious machine learning model to read sensitive files from the computer loading it. By providing a specially crafted ONNX model file, an attacker can bypass security boundaries to access local data or cause the application to crash. This poses a risk to any service that processes untrusted or user-uploaded AI models.

Technical details

The tract-onnx crate fails to sanitize the 'location' field in ONNX external data tensors. When joining the model directory with the provided location string, the library does not check for absolute paths or directory traversal sequences (e.g., '../'). An attacker can craft a model that, when loaded via model_for_path(), reads arbitrary local files into the model's tensors, which can then be retrieved via inference output. Additionally, providing out-of-bounds offset or length values for the external data can trigger a panic, leading to a denial of service. Patches are available in versions 0.21.17, 0.22.3, and 0.23.2.

Affected products

  • sonos tract-onnx < 0.21.17, >= 0.22.0, < 0.22.3, >= 0.23.0, < 0.23.2

Timeline

  • 2026-06-18: disclosed
  • 2026-06-19: advisory

References