Junglewise Threat Intelligence

CVE-2026-47612: NVIDIA Dynamo path traversal in image loading

CVE-2026-47612 · Severity: high · CVSS 7.5 · Published 2026-08-04

Technologies: Nvidia Dynamo, Linux Kernel. Vendors: Nvidia, Linux.

Executive brief

NVIDIA Dynamo for Linux is a tool that processes images as part of its core functionality. A flaw in how the image loading component handles file paths allows an attacker to read files outside of intended directories, potentially exposing sensitive information such as configuration files, credentials, or other confidential data.

Technical details

NVIDIA Dynamo for Linux contains a path traversal vulnerability in the image loading component due to improper limitation of pathname access to restricted directories. An attacker can craft a malicious image file or input that causes the application to access files outside the intended directory structure. This vulnerability is network-reachable if Dynamo processes untrusted image input from remote sources, or can be exploited locally if an attacker can control image files processed by the application. Successful exploitation leads to information disclosure. A patch is assumed to be available from NVIDIA.

Affected products

  • NVIDIA Dynamo <UNKNOWN>

Timeline

  • 2026-08-04: disclosed

References

Related threats