Executive brief
NVIDIA Dynamo for Linux is an AI/machine learning framework used to optimize and compile neural network models. A path traversal vulnerability allows attackers to read sensitive files on the system by supplying crafted local paths in multimodal requests, potentially exposing confidential data, model weights, or system configuration information.
Technical details
This vulnerability is a path traversal (improper pathname limitation) flaw in NVIDIA Dynamo for Linux. An attacker can supply a crafted local path within a multimodal request to bypass directory restrictions and access files outside the intended sandbox or restricted directory. The vulnerability is exploitable locally and requires only the ability to submit a crafted multimodal request to the Dynamo service. Successful exploitation results in information disclosure of files that should be protected. A patch or update from NVIDIA is likely available via their security advisories.
Affected products
- NVIDIA Dynamo <UNKNOWN>
Timeline
- 2026-08-04: disclosed