Impact
NVIDIA OpenShell’s Linux sandbox contains a path traversal flaw that permits bypass of L7 REST network policy checks. This weakness, identified as CWE-22, can allow an attacker to read unauthorized files or modify data within the sandbox, compromising both confidentiality and integrity.
Affected Systems
The vulnerability affects NVIDIA OpenShell running on Linux systems. No specific version range is listed, so all installations of the sandbox are potentially exposed until a vendor fix is applied.
Risk and Exploitability
The CVSS score of 8.5 indicates a high severity. The EPSS score is not available, and the issue is not yet listed in CISA KEV. The likely attack surface is through the L7 REST API, which could be accessed remotely if the network policy is misconfigured or bypassed. An attacker who can influence the REST calls or supply crafted inputs may trigger the traversal, leading to confidential data exposure or tampering.
OpenCVE Enrichment