Executive brief
NVIDIA Triton Inference Server is a widely-used inference platform for deploying machine learning models in production. A path traversal vulnerability could allow attackers to access unauthorized files on the system, potentially leading to denial of service or data exposure for organizations relying on this service for model inference.
Technical details
This is a path traversal vulnerability (CWE-22) in NVIDIA Triton Inference Server for Linux. The vulnerability allows an attacker to traverse the file system and access files outside the intended directory scope. The attack can be performed remotely over the network without authentication required. A successful exploit could result in denial of service by corrupting or deleting critical files, or exposure of sensitive model artifacts and configuration data. Patches are expected to be available from NVIDIA.
Affected products
- NVIDIA Triton Inference Server <UNKNOWN>
Timeline
- 2026-08-18: disclosed