synced 1 MIN AGO
01 Record

CVE-2026-55832

Tract: Arbitrary file read via unsanitized ONNX external_data `location` (path traversal) on model load in tract-onnx

MediumPUBLISHEDCNA: GitHub_M
CNA base score6.1 CVSS v3.xCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:L

02 Description

Tract: Arbitrary file read via unsanitized ONNX external_data `location` (path traversal) on model load in tract-onnx

03 Exploitation and scoring

Exploitation
Public exploit code exists. CISA's assessment records a public proof of concept. That is not a report of exploitation in the wild.
SSVC decision
  • ExploitationpocPublic proof-of-concept exploit code exists. Not a report of exploitation in the wild.
  • AutomatablenoAt least one step from reconnaissance to exploitation cannot be reliably automated.
  • Technical ImpactpartialSuccessful exploitation gives limited control of the vulnerable component.
CISA publishes the decision points, not a final SSVC decision. The decision also depends on mission and well-being impact, which is a property of your deployment rather than of the vulnerability.
EPSS probability
Not scored by EPSS
EPSS percentile
Not scored by EPSS
NVD base score
The NVD has published no score for this record
NVD CVSS vector
No NVD score to derive
NVD analysis status
Not recorded
Red Hat severity
No Red Hat rating. Red Hat rates the CVEs that affect its products.

Exploit-prediction scores from FIRST. Independent scoring and analysis status from the NVD. Vendor severity from Red Hat. Exploitation assessment and catalog membership from CISA.

04 Metadata

Published
2026-09-14 17:57Z1 HR AGO
Last updated
2026-09-14 18:12Z49 MIN AGO
Reserved
2026-06-17
Assigning CNA
GitHub_M
Record state
PUBLISHED
Severity
Medium (CVSS 6.1)
CNA CVSS vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:L
Weaknesses
  • CWE-22Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')Base
Data version
5.2
Document digest
e970d169ff8ae07a3353da3575a933632648280cad64762a95dad749d3fb2578

05 Affected products

VendorProductVersionsPlatforms
sonostract< 0.21.17, >= 0.22.0, < 0.22.3, >= 0.23.0, < 0.23.2

06 References