Opening SecureFlowNVIDIA Triton Python Backend Unauthenticated RCE Chain
Case summary & sources

AIDEFEND SecureFlow / SecureFlow Case Index

Wiz Research and NVIDIA aidefend-sf0022

NVIDIA Triton Python Backend Unauthenticated RCE Chain

  • AI Infrastructure
  • System Compromise & RCE
  • Data Exfiltration

Wiz disclosed a chain in NVIDIA Triton Inference Server's Python backend where an unauthenticated remote request leaks an internal shared-memory name, the public shared-memory API accepts that private key, attacker-controlled requests gain read/write access to backend IPC memory, and memory or IPC corruption can lead to remote code execution and AI-server takeover.

Mapped threat techniques

Source