Executive brief
NVIDIA Triton Inference Server, a platform used to deploy and manage AI models in production, is affected by a path traversal vulnerability. An attacker can exploit this flaw to interfere with the server's file handling, potentially causing the service to crash or become unavailable. This could disrupt AI-driven business operations and applications relying on the server for real-time predictions.
Technical details
A path traversal vulnerability (CWE-22) exists in NVIDIA Triton Inference Server. The flaw allows an unauthenticated attacker with network access to provide specially crafted input that bypasses directory restrictions. According to the CVSS metrics, the primary impact of a successful exploit is a partial loss of availability (Denial of Service), while confidentiality and integrity remain unaffected. The vulnerability is reachable over the network without requiring user interaction or specific privileges.
Affected products
- NVIDIA Triton Inference Server
Timeline
- 2026-05-20: disclosed: Initial publication of the CVE record.