Versions of the package onnx before and including 1.15.0 are vulnerable to Out-of-bounds Read as the ONNXASSERT and ONNXASSERTM functions have an off by one string copy.
"https://github.com/pypa/advisory-database/blob/main/vulns/onnx/PYSEC-2024-223.yaml"