Impact
NVIDIA Dynamo for Linux includes a flaw that allows an attacker to supply a crafted URL in a multimodal request, enabling server‑side request forgery (SSRF). A successful exploitation can cause the server to make unintended network requests and reveal sensitive data, compromising confidentiality and potentially exposing internal resources. The vulnerability is based on CWE‑918, reflecting improper validation of user‑controlled input.
Affected Systems
The affected product is NVIDIA Dynamo for Linux. The vulnerability impacts installations of Dynamo running on Linux platforms, as specified by the CNA. No specific version range is provided in the available data.
Risk and Exploitability
The CVSS score of 7.5 indicates a high severity, yet the EPSS score is missing, so the current exploitation probability cannot be quantified. The vulnerability is not listed in CISA KEV, suggesting no known widespread exploitation yet. Attackers would need to be able to trigger a multimodal request to the vulnerable instance, likely through network or application‑level access. The lack of a publicly available exploit reduces immediate threat, but the high severity warrants timely remediation.
OpenCVE Enrichment