Impact
The vulnerability appears in NVIDIA Dynamo for Linux within the Rust multimodal media fetcher and allows an attacker to perform server‑side request forgery. This flaw can be used to direct the server to make arbitrary HTTP requests to internal or external resources, potentially exposing sensitive data from those services. The impact is limited to information disclosure without any evidence of code execution or denial of service.
Affected Systems
The affected product is NVIDIA Dynamo for Linux. Specific affected versions have not been disclosed in the available information.
Risk and Exploitability
The CVSS base score of 7.5 rates this flaw as high severity, but the EPSS is not provided and it does not appear in the CISA KEV list. Because the flaw relies on the service accepting user‑supplied URLs, exploitation would most likely occur from an externally exposed interface, provided the attacker can supply a crafted request. The lack of additional context about network restrictions makes the actual exploitability uncertain.
OpenCVE Enrichment