Database/AI/ML frameworks & serving
NVIDIA NeMo Speech: code injection from malicious input, no user interaction needed
Impact
Malicious input causes code injection, giving code execution, information disclosure and data tampering. This id differs from the other NeMo Speech issues in the same bulletin in the way that matters operationally: it needs no user interaction and only low privileges (PR:L/UI:N), so an automated pipeline that ingests attacker-influenced input triggers it on its own rather than waiting for someone to open a file. On a shared GPU node that means any local account or job that can feed input to a NeMo Speech process can execute code with that process's access to datasets, checkpoints and the assigned GPUs.
Who can reach it
A local user or job with low privileges that can supply input to a NeMo Speech process. Authentication at the low-privilege level is needed; no user interaction.
What to do
Update NeMo Speech per NVIDIA security bulletin 2026/5885 and restart the processes and pipelines that embed it. The record does not state a fixed version - take it from the bulletin. Until then, do not run NeMo Speech ingestion on input that untrusted local accounts or tenants can influence.
References
Related entries
- NVIDIA NeMo Speech: malicious input data leads to remote code executionCVE-2026-24239 · NVIDIA NeMo SpeechHigh
- PyTorch (flatbuffer model parsing, torch::load / parse_and_initialize_mobile_module): MALICIOUS MODEL FILE TO MEMORYNCVD-2025-019-pytorch-flatbuffer-model-parsing · PyTorch (flatbuffer model parsing, torch::load / parse_and_initialize_mobile_module)High
- LangChain (Web Research Retriever): SSRFCVE-2024-3095 · LangChain (Web Research Retriever)High
- LangGraph MongoDB checkpoint and store: filter dicts allow MQL operator injection across tenantsCVE-2026-55253 · langgraph-checkpoint-mongodb / langgraph-store-mongodb (MongoDBSaver.list, MongoDBStore.search filters)High
- Kedro-Datasets PyTorchDataset: torch.load without weights_only executes code from .pt filesCVE-2026-62997 · kedro-datasets PyTorchDataset (kedro_datasets_experimental.pytorch)High
- SitemapLoader: nested sitemap entries skip restrict_to_same_domain, giving readable SSRFCVE-2026-72848 · langchain-community SitemapLoader (nested sitemap index entries)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.