GPU VulnDB

Database/NVIDIA / GPU stack

NeMo Framework: Unsafe deserialization of untrusted model/config data allows arbitrary code execution

CVSS 7.8CVE-2025-33241NVIDIA / GPU stack+5 more CVEscurated

Impact

A user or pipeline that loads an attacker-supplied checkpoint, config or other serialized artifact executes arbitrary code with the privileges of the training process. NVIDIA split this across 6 ids (CVE-2025-33241, -33243, -33250, -33251, -33252, -33253) in advisory 2026/5762, one per affected load path; all carry CVSS 7.8 and all are closed by the same release.

Who can reach it

Malicious checkpoint

What to do

Upgrade NeMo Framework to the fixed release from NVIDIA advisory 2026/5762 and rebuild training images; one bump closes all six ids. Until then, only load checkpoints and configs from sources you trust.

Also covers 5 CVEs

The vendor assigned a separate id to each affected code path. They share this advisory, this score and this fix, so they are one entry here.

CVE-2025-33243CVE-2025-33250CVE-2025-33251CVE-2025-33252CVE-2025-33253

References

Related entries

All NVIDIA / GPU stack entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.