NVIDIA AIStore - AuthN: A flaw in the AIStore authentication component reaches privilege escalation, information
CVSS 8.8CVE-2025-33186NVIDIA / GPU stackcurated
Impact
A flaw in the AIStore authentication component reaches privilege escalation, information disclosure and data tampering - effectively an authentication bypass in front of your training data store. Scored 8.8 network with no privileges required.
Who can reach it
Network, unauthenticated, one user-interaction step. Anyone with a route to AIStore's AuthN service.
What to do
Upgrade AIStore per bulletin 5724 as a priority and rotate AuthN tokens afterwards - the patch does not invalidate credentials an attacker may already hold. Cost: rolling control-plane restart.
References
Related entries
- NVIDIA AIStore - AuthN: An unauthenticated user extracts information from the AIStore authentication componentCVE-2025-33185 · NVIDIA AIStore - AuthNMedium
- NVIDIA TAO Toolkit: An uncontrolled search path loads an attacker-planted resource, reaching privilege escalationCVE-2025-33208 · NVIDIA TAO ToolkitHigh
- NVIDIA Merlin Transformers4Rec: The Trainer component deserializes untrusted data, reaching code executionCVE-2025-33213 · NVIDIA Merlin Transformers4RecHigh
- NVIDIA NVTabular: The Workflow component deserializes untrusted data, reaching code executionCVE-2025-33214 · NVIDIA NVTabularHigh
- BioNeMo Framework: Remote RCE via untrusted serializationCVE-2026-24164 · BioNeMo FrameworkHigh
- NVIDIA FLARE SDK: RCE via unsafe deserialization in message handlingCVE-2026-24186 · NVIDIA FLARE SDKHigh
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.