Impact
NVIDIA OpenShell for Linux contains a flaw in its inference proxy that permits improper encoding or escaping of output. A successful exploitation can lead to the unintended disclosure of data and alteration of output intended for downstream consumers, potentially compromising confidentiality and integrity of information processed by the system.
Affected Systems
The affected product is NVIDIA OpenShell for Linux. No specific version information is provided, so all releases of this product are potentially impacted until a fix is released.
Risk and Exploitability
The CVSS score of 5.2 indicates a moderate risk level. The EPSS score is not available and the vulnerability is not listed in CISA KEV, suggesting a lower likelihood of widespread exploitation. The attack vector is inferred to be remote, leveraging the inference proxy interface that clients can connect to over a network. Without an official workaround, the safest approach is to apply the vendor patch if available or otherwise restrict access to the inference proxy.
OpenCVE Enrichment