Executive brief
NVIDIA Triton Inference Server is a software platform used to deploy and run AI/ML inference models at scale. An attacker could exploit a path traversal vulnerability to read arbitrary files from the server's filesystem and potentially execute malicious code, compromising model integrity and exposing sensitive data.
Technical details
The vulnerability is a path traversal flaw in NVIDIA Triton Inference Server for Linux that allows an attacker to access files outside intended directories using absolute paths. The attack is network-reachable and could lead to both information disclosure (reading arbitrary files) and remote code execution. No specific preconditions such as authentication are mentioned. The vulnerability was published on 2026-08-18 with a CVSS score of 6.5 (medium severity).
Affected products
- NVIDIA Triton Inference Server <UNKNOWN>
Timeline
- 2026-08-18: disclosed