NVIDIA NeMo Agent Toolkit (Web UI): The chat API endpoint is vulnerable to server-side request forgery, so an attacker
Impact
The chat API endpoint is vulnerable to server-side request forgery, so an attacker makes the toolkit issue requests to internal endpoints - cloud metadata services and in-cluster APIs being the obvious targets. In an AI datacenter this is the model-and-data supply chain problem: the code runs with whatever the training or inference job holds, which is usually a GPU, a service account, and mounted object storage credentials.
Who can reach it
Requires the job to load an attacker-influenced artifact - a checkpoint, .nemo file, config, tokenizer or dataset. Any pipeline that pulls from a public model hub, a customer bucket, or a tenant-supplied path is in scope.
What to do
Bump the package to the fixed version in bulletin 5726 and rebuild every training/inference image that embeds it. Cost: image rebuild and job restart; no host driver or firmware change. The durable control is refusing to deserialize untrusted checkpoints at all - prefer safetensors-style formats and treat pickle-bearing artifacts as executable code.
References
Related entries
- NVIDIA Jetson Linux (initrd command-line handling): An attacker with physical access and no credentials at all canCVE-2026-24154 · NVIDIA Jetson Linux (initrd command-line handling)High
- NVIDIA GPU firmware microcontroller (Falcon): A privileged user can craft microcode that the GPU's internalCVE-2021-23201 · NVIDIA GPU firmware microcontroller (Falcon)High
- NVIDIA GPU firmware microcontroller (Falcon): A privileged user can time a DMA write from the GPU's internalCVE-2021-23217 · NVIDIA GPU firmware microcontroller (Falcon)High
- NVIDIA DGX A100 - SBIOS / SMM firmware: An integer overflow in SmmCore, chainable from another bug, reaches SMM codeCVE-2022-31600 · NVIDIA DGX A100 - SBIOS / SMM firmwareHigh
- NVIDIA DGX A100 - SBIOS / SMM firmware: The SmiFlash SMM handler lets a privileged local user read, write and eraseCVE-2022-42276 · NVIDIA DGX A100 - SBIOS / SMM firmwareHigh
- NVIDIA DGX Station - SBIOS / SMM firmware: The same SmiFlash read/write/erase primitive on DGX Station, givingCVE-2022-42277 · NVIDIA DGX Station - SBIOS / SMM firmwareHigh
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.