CVE-2024-7776

CVSS 3.1 Score 9.1 of 10 (high)

Details

Published Mar 20, 2025
Updated: Mar 26, 2025
CWE ID 22

Summary

CVE-2024-7776 is a newly identified vulnerability affecting the `download_model` function in onnx/onnx framework versions prior to 1.16.1. The issue stems from insufficient protection against path traversal assaults in malicious tar files. An assailant can take advantage of this weakness to overwrite files within the user's directory, potentially leading to remote command execution. This vulnerability poses a significant risk for unauthorized system access and data manipulation. Users are strongly advised to update their onnx/onnx framework to a patched version as soon as possible to mitigate this threat.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share