CVE-2026-47487: Path Traversal
NVIDIA Triton Inference Server for Linux contains a vulnerability where a user could cause files outside the model repository to be read, written to, or modified by providing a path in the model name to the Triton MLflow plugin. A successful exploit of this vulnerability might lead to denial of service and information disclosure.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-47487?
The severity of CVE-2026-47487 is rated as medium with a CVSS score of 4.4.
How do I fix CVE-2026-47487?
To mitigate CVE-2026-47487, ensure that the model name provided to the Triton MLflow plugin does not include paths that can lead to file traversal.
What type of vulnerability is CVE-2026-47487?
CVE-2026-47487 is a path traversal vulnerability in the NVIDIA Triton Inference Server for Linux.
What can happen if CVE-2026-47487 is exploited?
Exploitation of CVE-2026-47487 may allow unauthorized reading, writing, or modification of files outside the model repository.
Who is affected by CVE-2026-47487?
The vulnerability affects users of the NVIDIA Triton Inference Server for Linux that utilize the Triton MLflow plugin.