VYPR
High severity8.8NVD Advisory· Published May 20, 2026

CVE-2026-24217

CVE-2026-24217

Description

NVIDIA BioNeMo Core for Linux contains a vulnerability where a user could cause a path traversal by loading a malicious file. A successful exploit of this vulnerability might lead to code execution, denial of service, information disclosure, and data tampering.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

NVIDIA BioNeMo Core for Linux contains a path traversal vulnerability allowing file loading to achieve code execution, DoS, info disclosure, and data tampering.

Vulnerability

NVIDIA BioNeMo Core for Linux contains a path traversal vulnerability [1]. A user can trigger a path traversal by loading a malicious file, potentially escaping the intended directory. The exact affected versions are not disclosed in the available reference, but the issue affects the Linux distribution of BioNeMo Core.

Exploitation

To exploit the vulnerability, an attacker must be able to load a malicious file into the application. The vector is path traversal, meaning the malicious file can reference paths outside the intended scope. No further details on required privileges or network position are provided in the reference.

Impact

Successful exploitation could lead to code execution, denial of service, information disclosure, and data tampering [1]. This indicates a full compromise of confidentiality, integrity, and availability. The attacker may achieve arbitrary code execution within the context of the application.

Mitigation

As of the publication date (2026-05-20), no fixed version or workaround has been disclosed in the available references [1]. Users are advised to monitor NVIDIA's official security advisories for patches. If no update is expected, consider isolating the application or applying strict file input validation.

AI Insight generated on May 21, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

3

News mentions

0

No linked articles in our index yet.