{"id":"CVE-2026-28500","aliases":["GHSA-hqmj-h5c6-369m","PYSEC-2026-103"],"title":"ONNX Untrusted Model Repository Warnings Suppressed by silent=True in onnx.hub.load() — Silent Supply-Chain Attack","summary":"ONNX Untrusted Model Repository Warnings Suppressed by silent=True in onnx.hub.load() — Silent Supply-Chain Attack","severity":"high","cvss":8.6,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N","vendor":"onnx","product":"onnx","ecosystem":"pip","affected":["onnx < 1.21.0rc1"],"patched":["onnx 1.21.0rc1"],"published":"2026-03-16","updated":"2026-09-10","sourceUpdated":"2026-09-10T03:50:39.607200051Z","source":"OSV","sourceUrl":"https://osv.dev/vulnerability/GHSA-hqmj-h5c6-369m","references":[{"url":"https://github.com/onnx/onnx/security/advisories/GHSA-hqmj-h5c6-369m"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-28500"},{"url":"https://github.com/ZeroXJacks/CVEs/blob/main/2026/CVE-2026-28500.md"},{"url":"https://github.com/onnx/onnx"},{"url":"https://github.com/pypa/advisory-database/tree/main/vulns/onnx/PYSEC-2026-103.yaml"}],"tags":["osv","pip"],"epss":0.00318,"epssPercentile":0.24854,"ingestedAt":"2026-09-12T03:13:01.701Z","slug":"CVE-2026-28500","body":"## Overview\n\n## What's the issue\nPassing `silent=True` to `onnx.hub.load()` kills all trust warnings and user prompts. This means a model can be downloaded from any unverified GitHub repo with zero user awareness.\n \n```python\nif not _verify_repo_ref(repo) and not silent:\n    # completely skipped when silent=True\n    print(\"The model repo... is not trusted\")\n    if input().lower() != \"y\":\n        return None\n```\n \nOn top of that, the SHA256 integrity check is useless here — it validates against a manifest that lives in the same repo the attacker controls, so the hash will always match.\n\n \n## Impact\nAny pipeline using `hub.load()` with `silent=True` and an external repo string is silently loading whatever the repo owner ships. If that model executes arbitrary code on load, the attacker has access to the machine.\n \n## Resolved by removing the feature \n## References\n \n- [Write-up](https://github.com/ZeroXJacks/CVEs/blob/main/2026/CVE-2026-28500.md)\n\n## Affected packages\n\n- `onnx < 1.21.0rc1`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `onnx 1.21.0rc1`","depth":"twilight","depthScore":47,"depthScoreParts":{"impact":47.3,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}