CVE-2026-49114 Details
Description
In ONNX before 1.21.0, the 'save_external_data' function builds the external-data file path from the model's external_data location field and opens it for writing without 'O_NOFOLLOW/O_EXCL', after a non-atomic 'os.path.isfile()' check. A local attacker with write access to the directory where a victim serializes external data can deterministically pre-plant a symlink that is being followed, causing the victim's write to append to any file the victim can write, e.g. ~/.ssh/authorized_keys, cron files, or application configs. Fixed in 1.21.0.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Aug 21, 2026CISA-ADP
Assessed May 27, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/onnx/onnx/security/advisories/GHSA-q56x-g2fj-4rj6 | Cybersecurity and Infrastructure Security Agency (CISA) U.S. Civilian Government | ExploitVendor Advisory |
| https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-233-01.json | Cybersecurity and Infrastructure Security Agency (CISA) U.S. Civilian Government | VDB Entry |
| https://www.cve.org/CVERecord?id=CVE-2026-49114 | Cybersecurity and Infrastructure Security Agency (CISA) U.S. Civilian Government | Third Party AdvisoryVDB Entry |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-22 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') | Cybersecurity and Infrastructure Security Agency (CISA) U.S. Civilian Government |
| CWE-367 | Time-of-check Time-of-use (TOCTOU) Race Condition | Cybersecurity and Infrastructure Security Agency (CISA) U.S. Civilian Government |
| CWE-59 | Improper Link Resolution Before File Access ('Link Following') | Cybersecurity and Infrastructure Security Agency (CISA) U.S. Civilian Government |
Affected Products
| Product | Versions |
|---|---|
| linuxfoundation onnx | < 1.21.0 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 16, 2026 | Reanalysis | [email protected] |
| Sep 16, 2026 | Initial Analysis | [email protected] |
| Aug 21, 2026 | CVE Modified | CISA-ADP |
| Aug 21, 2026 | New CVE Received | Cybersecurity and Infrastructure Security Agency (CISA) U.S. Civilian Government |