Path traversal in Triton Inference Server - CVE-2026-24147
Published: May 18, 2026
Triton Inference Server
Detailed vulnerability description
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to path traversal in triton server when uploading a model configuration. A remote attacker can upload a crafted model configuration to disclose sensitive information.
The advisory also notes that successful exploitation may lead to a denial of service.