LIVE · cybersecurity feed
Live wire
cve recordhigh

CVE-2026-28500

linuxfoundation · onnx

Published
CVSS8.6
Severityhigh
WeaknessCWE-345
ExploitedNot in CISA KEV

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N

Description

Open Neural Network Exchange (ONNX) is an open standard for machine learning interoperability. In versions up to and including 1.20.1, a security control bypass exists in onnx.hub.load() due to improper logic in the repository trust verification mechanism. While the function is designed to warn users when loading models from non-official sources, the use of the silent=True parameter completely suppresses all security warnings and confirmation prompts. This vulnerability transforms a standard model-loading function into a vector for Zero-Interaction Supply-Chain Attacks. When chained with file-system vulnerabilities, an attacker can silently exfiltrate sensitive files (SSH keys, cloud credent

References

← Back to the CVE Tracker

Our coverage of CVE-2026-28500

No stories yet. This page updates automatically when we publish reporting that references CVE-2026-28500.