NeMo Framework: Unsafe deserialization of untrusted model/config data allows arbitrary code execution
Impact
A user or pipeline that loads an attacker-supplied checkpoint, config or other serialized artifact executes arbitrary code with the privileges of the training process. NVIDIA split this across 6 ids (CVE-2025-33241, -33243, -33250, -33251, -33252, -33253) in advisory 2026/5762, one per affected load path; all carry CVSS 7.8 and all are closed by the same release.
Who can reach it
Malicious checkpoint
What to do
Upgrade NeMo Framework to the fixed release from NVIDIA advisory 2026/5762 and rebuild training images; one bump closes all six ids. Until then, only load checkpoints and configs from sources you trust.
Also covers 5 CVEs
The vendor assigned a separate id to each affected code path. They share this advisory, this score and this fix, so they are one entry here.
References
Related entries
- NeMo Framework: Local command injection via unsanitized input passed to shell executionCVE-2025-33246 · NeMo FrameworkHigh
- NeMo Framework: RCE via malicious YAML deserializationCVE-2026-24155 · NeMo FrameworkHigh
- NeMo Framework: unsafe deserialization of untrusted model data allows remote code executionCVE-2026-24157 · NeMo FrameworkHigh
- NeMo Framework: RCE via unsafe object deserializationCVE-2026-24228 · NeMo FrameworkHigh
- NeMo Framework: Command injection in script processingCVE-2026-24250 · NeMo FrameworkHigh
- NeMo Framework: RCE via insecure deserializationCVE-2025-23249 · NeMo FrameworkHigh
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.