CVE-2026-49114 | ONNX up to 1.20.x External Data save_external_data symlink

SecurityVulns

A vulnerability classified as problematic has been found in ONNX up to 1.20.x. Affected by this vulnerability is the function save_external_data of the component External Data. This manipulation causes symlink following.

This vulnerability is handled as CVE-2026-49114. It is possible to launch the attack on the local host. There is not any exploit available.

It is recommended to upgrade the affected component.VulDB Recent EntriesRead More