CVE-2026-24217
published 2026-05-20CVE-2026-24217: NVIDIA BioNeMo Core for Linux contains a vulnerability where a user could cause a path traversal by loading a malicious file. A successful exploit of this…
PriorityP346high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
EPSS
0.76%
51.3th percentile
NVIDIA BioNeMo Core for Linux contains a vulnerability where a user could cause a path traversal by loading a malicious file. A successful exploit of this vulnerability might lead to code execution, denial of service, information disclosure, and data tampering.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| nvidia | bionemo_framework | < commit dfd83a7 on main | commit dfd83a7 on main |
| nvidia | bionemo_framework | < 2026-04-03 | 2026-04-03 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
NVIDIA BioNeMo Framework on Linux File path traversal
vuldb·2026-05-20·CVSS 8.8
CVE-2026-24217 [HIGH] NVIDIA BioNeMo Framework on Linux File path traversal
A vulnerability was found in NVIDIA BioNeMo Framework on Linux. It has been rated as very critical. The affected element is an unknown function of the component File Handler. The manipulation leads to path traversal: '\..\filename'.
This vulnerability is documented as CVE-2026-24217. The attack can be initiated remotely. There is not any exploit available.
GHSA
GHSA-3wq4-xjpf-pj4j: NVIDIA BioNeMo Core for Linux contains a vulnerability where a user could cause a path traversal by loading a malicious file
ghsa_unreviewed·2026-05-20
CVE-2026-24217 [HIGH] CWE-29 GHSA-3wq4-xjpf-pj4j: NVIDIA BioNeMo Core for Linux contains a vulnerability where a user could cause a path traversal by loading a malicious file
NVIDIA BioNeMo Core for Linux contains a vulnerability where a user could cause a path traversal by loading a malicious file. A successful exploit of this vulnerability might lead to code execution, denial of service, information disclosure, and data tampering.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-05-20
Published