Impact
ONNX before 1.16.2 contains a path traversal vulnerability in download_model_with_test_data. Public advisories describe arbitrary file overwrite risk when a vulnerable runtime extracts a malicious model test-data archive. The practical impact depends on whether an application calls this helper on model archives from untrusted or attacker-influenced sources. [S1][S2][S3]
Root cause
The vulnerable helper extracted model test-data archives without fully constraining archive member paths to the intended destination. That can let archive entries escape the extraction directory when the affected helper processes a crafted archive. [S1][S2]
Affected versions
PyPI onnx releases before 1.16.2 are affected. Upgrade to onnx 1.16.2 or a later maintained release, then rebuild any training, inference, notebook, CI, worker, or model-ingestion runtime that installs ONNX. [S1][S2]
Remediation
Upgrade the active ONNX dependency source, regenerate the relevant Python lockfile, rebuild deployed images or virtual environments, and verify the runtime version with your package manager. Review any download_model_with_test_data call sites so model test-data archives come only from trusted, provenance-checked sources and extract into controlled scratch locations.
Covered by FixVibe
FixVibe's GitHub repo scans flag affected onnx versions for CVE-2024-5187 / GHSA-6rq9-53c3-f7vj and point to any download_model_with_test_data call in your Python source.
