NVIDIA TensorRT-LLM Python Executor Data Validation Vulnerability Allowing Code Execution

Vulnerability

A vulnerability exists in the Python executor of NVIDIA TensorRT-LLM on all platforms, prior to version 0.18.2. This issue allows an attacker with local access to the TRTLLM server to cause a data validation problem, which could be exploited to execute code, disclose information, and tamper with data.

Impact

Exploitation of this vulnerability could lead to unauthorized code execution, information disclosure, and data manipulation.

Remediation

Users are advised to upgrade to version 0.18.2 or later. Instructions for downloading the latest release are available on the NVIDIA TensorRT GitHub releases page.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
7.5
exploitability
3.3
remediation
7.7
relevance
0.0
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.