Impact
NVIDIA Dynamo for Linux contains a server‑side request forgery flaw in its multimodal media fetcher. The vulnerability allows an attacker to compel the server to make arbitrary HTTP requests, potentially exposing internal or external resources. Successful exploitation could lead to information disclosure, compromising confidentiality. This issue is classified as CWE‑918, reflecting the injection of arbitrary URLs into server‑side requests.
Affected Systems
The flaw affects NVIDIA Dynamo for Linux deployments; no specific product versions are currently listed as impacted. Any installation that includes the multimodal media fetcher is potentially vulnerable until a vendor patch or mitigation is applied.
Risk and Exploitability
The CVSS score of 7.5 indicates moderate to high severity. The EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog, suggesting that public exploitation has not yet been observed. Based on the description, it is inferred that the attack vector is remote, requiring network reach to the NVIDIA Dynamo instance. The potential impact is information disclosure, but the likelihood of exploitation remains uncertain without known public exploits.
OpenCVE Enrichment