Impact
NVIDIA Dynamo for Linux contains a path‑traversal flaw in its image loading component. The flaw permits an attacker to supply a pathname that bypasses the intended directory restrictions, potentially enabling access to files outside the allowed area and resulting in the disclosure of sensitive information.
Affected Systems
The affected product is NVIDIA Dynamo for Linux. No specific version range is listed, so the vulnerability may impact all releases prior to a vendor patch. Only NVIDIA is identified as the vendor.
Risk and Exploitability
The CVSS score of 7.5 reflects a high level of severity. No EPSS score is provided, so the likelihood of exploitation is uncertain. The vulnerability is not listed in the CISA KEV catalog, suggesting no confirmed commercial exploitation yet. The likely attack vector is inferred to be local, but could be remote if the image loader accepts externally supplied inputs; explicit details are not provided in the advisory.
OpenCVE Enrichment