GPU VulnDB

Database/AI/ML frameworks & serving

NVIDIA NeMo Speech: malicious input data leads to remote code execution

CVSS 7.8CVE-2026-24239AI/ML frameworks & servingcurated

Impact

A crafted data file processed by NeMo Speech gets the attacker code execution in the context of the process handling it, plus information disclosure and data tampering. On a GPU fleet that means whoever supplies a speech dataset or model artifact - a tenant, a data pipeline, an untrusted corpus - can run code inside the training or preprocessing job, with access to that job's credentials, mounted datasets and the GPUs assigned to it. NVIDIA scores it 7.8 local with user interaction required, so the realistic path is an operator or pipeline opening attacker-supplied data rather than a network-facing service. The record does not identify the vulnerable code path, so blast radius beyond the processing job is unestablished.

Who can reach it

No authentication to the toolkit itself; the attacker only needs to get a malicious data file in front of a NeMo Speech workflow. User interaction is required (someone must load the data), and the CVSS vector is local (AV:L).

What to do

Update NeMo Speech per NVIDIA security bulletin 2026/5885 and restart any jobs or services that use it. The record does not state a fixed version - read the bulletin for the exact release. Until updated, treat externally supplied speech datasets and manifests as untrusted input and process them in a sandboxed job with no cluster credentials mounted.

References

Related entries

All AI/ML frameworks & serving entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.