Impact
The NVIDIA Triton Inference Server for Linux contains a path traversal flaw in the MLflow plugin. By including a specially crafted path in the model name, an attacker may be able to read, write, or modify files located outside the designated model repository. The vulnerability can lead to information disclosure and may also cause a denial of service if critical files are altered or deleted.
Affected Systems
Vendor NVIDIA provides the Triton Inference Server for Linux. The flaw applies to all releases of the server that have the MLflow plugin enabled; specific version ranges are not supplied by the advisory.
Risk and Exploitability
The CVSS score is 4.4, indicating a moderate severity. EPSS information is not available, and the vulnerability is not listed in the CISA KEV catalog. The attack vector is inferred to involve supplying a manipulated model name to the MLflow plugin; it may require local access or an exposed API endpoint. The path traversal weakness, CWE‑22, allows local or remote attackers to read or alter files outside the intended directory, potentially leading to executing arbitrary code or tampering with model data.
OpenCVE Enrichment