NVIDIA NeMo Framework: Crafted data reaches code injection and privilege escalation in the job context
Impact
Crafted data reaches code injection and privilege escalation in the job context. In an AI datacenter this is the model-and-data supply chain problem: the code runs with whatever the training or inference job holds, which is usually a GPU, a service account, and mounted object storage credentials.
Who can reach it
Requires the job to load an attacker-influenced artifact - a checkpoint, .nemo file, config, tokenizer or dataset. Any pipeline that pulls from a public model hub, a customer bucket, or a tenant-supplied path is in scope.
What to do
Bump the package to the fixed version in bulletin 5736 and rebuild every training/inference image that embeds it. Cost: image rebuild and job restart; no host driver or firmware change. The durable control is refusing to deserialize untrusted checkpoints at all - prefer safetensors-style formats and treat pickle-bearing artifacts as executable code.
References
Related entries
- NVIDIA NeMo Framework: OS command injection reaches code execution with the job's privilegesCVE-2026-24252 · NVIDIA NeMo FrameworkHigh
- NVIDIA NeMo Framework: A predefined variable pulls in functionality from an untrusted control sphere, reaching codeCVE-2025-33205 · NVIDIA NeMo FrameworkHigh
- NVIDIA NeMo Framework: Loading a maliciously crafted model file bypasses the framework's control mechanisms and reachesCVE-2025-33212 · NVIDIA NeMo FrameworkHigh
- NVIDIA NeMo Framework: A relative path traversal gives arbitrary file write, reaching code executionCVE-2025-23360 · NVIDIA NeMo FrameworkHigh
- NVIDIA NeMo Framework: Deserialization of untrusted data reaches remote code execution when a crafted artifactCVE-2025-23303 · NVIDIA NeMo FrameworkHigh
- NVIDIA NeMo Framework: Loading a .nemo file with crafted metadata injects code at model-load timeCVE-2025-23304 · NVIDIA NeMo FrameworkHigh
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.