NVIDIA NeMo Framework: Loading a maliciously crafted model file bypasses the framework's control mechanisms and reaches
Impact
Loading a maliciously crafted model file bypasses the framework's control mechanisms and reaches code execution. In an AI datacenter this is the model-and-data supply chain problem: the code runs with whatever the training or inference job holds, which is usually a GPU, a service account, and mounted object storage credentials.
Who can reach it
Requires the job to load an attacker-influenced artifact - a checkpoint, .nemo file, config, tokenizer or dataset. Any pipeline that pulls from a public model hub, a customer bucket, or a tenant-supplied path is in scope.
What to do
Bump the package to the fixed version in bulletin 5736 and rebuild every training/inference image that embeds it. Cost: image rebuild and job restart; no host driver or firmware change. The durable control is refusing to deserialize untrusted checkpoints at all - prefer safetensors-style formats and treat pickle-bearing artifacts as executable code.
References
Related entries
- NVIDIA NeMo Framework: A relative path traversal gives arbitrary file write, reaching code executionCVE-2025-23360 · NVIDIA NeMo FrameworkHigh
- NVIDIA NeMo Framework: Deserialization of untrusted data reaches remote code execution when a crafted artifactCVE-2025-23303 · NVIDIA NeMo FrameworkHigh
- NVIDIA NeMo Framework: Loading a .nemo file with crafted metadata injects code at model-load timeCVE-2025-23304 · NVIDIA NeMo FrameworkHigh
- NVIDIA NeMo Framework: Crafted data in the retrieval-services component injects code into the running jobCVE-2025-23312 · NVIDIA NeMo FrameworkHigh
- NVIDIA NeMo Framework: crafted data in the NLP component injects code into the running job (CWE-94)CVE-2025-23313 · NVIDIA NeMo FrameworkHigh
- NVIDIA NeMo Framework: Crafted data in the export-and-deploy component injects codeCVE-2025-23315 · NVIDIA NeMo FrameworkHigh
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.