Junglewise Threat Intelligence

CVE-2026-47613: NVIDIA Dynamo path traversal vulnerability

CVE-2026-47613 · Severity: high · CVSS 7.5 · Published 2026-08-04

Technologies: Nvidia Dynamo, Linux Kernel. Vendors: Nvidia, Linux.

Executive brief

NVIDIA Dynamo for Linux is an AI/machine learning framework used to optimize and compile neural network models. A path traversal vulnerability allows attackers to read sensitive files on the system by supplying crafted local paths in multimodal requests, potentially exposing confidential data, model weights, or system configuration information.

Technical details

This vulnerability is a path traversal (improper pathname limitation) flaw in NVIDIA Dynamo for Linux. An attacker can supply a crafted local path within a multimodal request to bypass directory restrictions and access files outside the intended sandbox or restricted directory. The vulnerability is exploitable locally and requires only the ability to submit a crafted multimodal request to the Dynamo service. Successful exploitation results in information disclosure of files that should be protected. A patch or update from NVIDIA is likely available via their security advisories.

Affected products

  • NVIDIA Dynamo <UNKNOWN>

Timeline

  • 2026-08-04: disclosed

References

Related threats