Description
NVIDIA Dynamo for Linux contains a vulnerability where an attacker may cause improper limitation of a pathname to a restricted directory by supplying a crafted local path in a multimodal request. A successful exploit of this vulnerability might lead to information disclosure.
Published: 2026-08-04
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

NVIDIA Dynamo for Linux includes a flaw in the handling of multimodal requests that allows an attacker to craft a local path reference outside the intended restrictions. This improper limitation of a pathname could enable the attacker to read files that should remain protected, resulting in potential information disclosure. The weakness is categorized as CWE-918, indicating a path traversal vulnerability.

Affected Systems

The affected product is NVIDIA Dynamo for Linux. No specific version numbers were supplied in the advisory, so any release prior to the application of a vendor fix may be vulnerable. Organizations should verify the build and consult NVIDIA's release notes for remediation information.

Risk and Exploitability

The CVSS score of 7.5 places this issue in the high severity range. While EPSS data is not available, the lack of inclusion in the CISA KEV catalog suggests no known exploitation at the time of analysis. The exploit appears to be local, requiring the attacker to run a multimodal request on the system. Successful exploitation could expose confidential configuration or data files located in restricted directories.

Generated by OpenCVE AI on August 4, 2026 at 19:22 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Inspect NVIDIA's security advisories and install any available patches for NVIDIA Dynamo for Linux.
  • Restrict the user or process rights that can submit multimodal requests to minimize local attack surface.
  • Implement additional guardrails in the application to enforce strict pathname bounds, preventing traversal to restricted directories.

Generated by OpenCVE AI on August 4, 2026 at 19:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 05 Aug 2026 10:45:00 +0000

Type Values Removed Values Added
First Time appeared Nvidia
Nvidia dynamo
Vendors & Products Nvidia
Nvidia dynamo

Tue, 04 Aug 2026 19:45:00 +0000

Type Values Removed Values Added
Title Improper Pathname Validation Allowing Exploit of Restricted Directories in NVIDIA Dynamo for Linux

Tue, 04 Aug 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 04 Aug 2026 17:45:00 +0000

Type Values Removed Values Added
Description NVIDIA Dynamo for Linux contains a vulnerability where an attacker may cause improper limitation of a pathname to a restricted directory by supplying a crafted local path in a multimodal request. A successful exploit of this vulnerability might lead to information disclosure.
Weaknesses CWE-918
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: nvidia

Published:

Updated: 2026-08-04T18:40:31.848Z

Reserved: 2026-05-19T19:55:51.494Z

Link: CVE-2026-47613

cve-icon Vulnrichment

Updated: 2026-08-04T18:40:26.883Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-04T18:16:50.750

Modified: 2026-08-07T19:30:50.473

Link: CVE-2026-47613

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-05T10:19:34Z

Weaknesses
  • CWE-918

    Server-Side Request Forgery (SSRF)