NeMo Framework: unsafe deserialization of untrusted model data allows remote code execution
Impact
Loading an untrusted model or checkpoint into NeMo Framework deserializes attacker-controlled data and executes arbitrary code with the privileges of the training or inference process, giving code execution inside GPU training images and on the data they can reach. NVIDIA split this across 2 CVE ids (CVE-2026-24157, CVE-2026-24159) covering the affected load paths, but they share one advisory, one severity and one fix.
Who can reach it
Malicious checkpoint
What to do
Upgrade NeMo Framework to the fixed release named in NVIDIA bulletin 5800 and rebuild/redeploy any training and inference container images that pin the old version; until then, only load models and checkpoints from trusted sources.
Also covers 1 CVE
The vendor assigned a separate id to each affected code path. They share this advisory, this score and this fix, so they are one entry here.
References
Related entries
- NeMo Framework: RCE via unsafe object deserializationCVE-2026-24228 · NeMo FrameworkHigh
- NeMo Framework: Command injection in script processingCVE-2026-24250 · NeMo FrameworkHigh
- NeMo Framework: RCE via insecure deserializationCVE-2025-23249 · NeMo FrameworkHigh
- NeMo Framework: Arbitrary file write/read via path traversalCVE-2025-23250 · NeMo FrameworkHigh
- NeMo Framework: RCECVE-2025-23251 · NeMo FrameworkHigh
- NeMo Framework: Remote RCE via insecure deserialization over the networkCVE-2025-33245 · NeMo FrameworkHigh
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.