Impact
NVIDIA Dynamo for Linux includes a flaw in the handling of multimodal requests that allows an attacker to craft a local path reference outside the intended restrictions. This improper limitation of a pathname could enable the attacker to read files that should remain protected, resulting in potential information disclosure. The weakness is categorized as CWE-918, indicating a path traversal vulnerability.
Affected Systems
The affected product is NVIDIA Dynamo for Linux. No specific version numbers were supplied in the advisory, so any release prior to the application of a vendor fix may be vulnerable. Organizations should verify the build and consult NVIDIA's release notes for remediation information.
Risk and Exploitability
The CVSS score of 7.5 places this issue in the high severity range. While EPSS data is not available, the lack of inclusion in the CISA KEV catalog suggests no known exploitation at the time of analysis. The exploit appears to be local, requiring the attacker to run a multimodal request on the system. Successful exploitation could expose confidential configuration or data files located in restricted directories.
OpenCVE Enrichment