CVE-2026-47613
published 2026-08-04CVE-2026-47613: NVIDIA Dynamo for Linux contains a vulnerability where an attacker may cause improper limitation of a pathname to a restricted directory by supplying a crafted…
PriorityP343high7.5CVSS 3.1
AVNACLPRNUINSUCHINAN
EPSS
0.32%
24.7th percentile
NVIDIA Dynamo for Linux contains a vulnerability where an attacker may cause improper limitation of a pathname to a restricted directory by supplying a crafted local path in a multimodal request. A successful exploit of this vulnerability might lead to information disclosure.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| nvidia | dynamo | <= 1.1.0 | — |
| nvidia | dynamo | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
NVIDIA Dynamo for Linux contains a vulnerability where an attacker may cause improper limitation of a pathname to a restricted directory by supplying a crafted local path in a multimodal request.
ghsa_unreviewed·2026-08-04
CVE-2026-47613 [HIGH] CWE-918 NVIDIA Dynamo for Linux contains a vulnerability where an attacker may cause improper limitation of a pathname to a restricted directory by supplying a crafted local path in a multimodal request.
NVIDIA Dynamo for Linux contains a vulnerability where an attacker may cause improper limitation of a pathname to a restricted directory by supplying a crafted local path in a multimodal request. A successful exploit of this vulnerability might lead to information disclosure.
VulDB
NVIDIA Dynamo information disclosure
vuldb·2026-08-04·CVSS 7.5
CVE-2026-47613 [HIGH] NVIDIA Dynamo information disclosure
A vulnerability marked as problematic has been reported in NVIDIA Dynamo. Impacted is an unknown function. The manipulation leads to information disclosure.
This vulnerability is uniquely identified as CVE-2026-47613. The attack is possible to be carried out remotely. No exploit exists.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-08-04
Published