Executive brief
Netron is a popular model viewer application used to visualize neural network and machine learning model architectures. A reflected cross-site scripting vulnerability allows attackers to craft malicious model files that execute arbitrary JavaScript when opened, potentially enabling port scanning of local network services, UI manipulation, and when chained with Chrome/V8 vulnerabilities, remote code execution on the user's system.
Technical details
Netron contains a DOM-based XSS vulnerability (CWE-79) where user-controlled model fields (node names, input/output descriptions) are directly inserted into innerHTML without HTML escaping. The vulnerability is triggered when a user opens a crafted malicious model file (ONNX or other supported format) and clicks nodes in the sidebar to view details. While Netron implements a Content-Security-Policy blocking inline scripts, the policy lacks frame-src restrictions, allowing attacker-controlled iframes to execute scripts freely. An attacker with network access can deliver malicious model files via phishing or network interception, and the JavaScript context has unrestricted access to local network services and the Electron/Chromium runtime. Patches are available in Netron version 9.1.3 and later.
Affected products
- Netron Netron up to and including 9.1.2
Timeline
- 2026-08-27: disclosed: Vulnerability disclosed and patched in version 9.1.3
- 2026-08-27: advisory: CVE-2026-79720 assigned