GPU VulnDB

Database/AI/ML frameworks & serving

NVIDIA Model-Optimizer: deserialization of untrusted data leads to code execution

CVSS 7.8CVE-2026-65142AI/ML frameworks & servingcurated

Impact

Model-Optimizer is the quantization and sparsification toolchain teams run before serving a model on TensorRT or Triton. It deserializes untrusted input, so a crafted checkpoint or artifact handed to the optimizer executes code with the privileges of the user running it, and can also tamper with the resulting model or leak data from the job. On a shared GPU fleet the realistic path is a model pulled from a hub or supplied by a tenant and then optimized by a pipeline account that is often more privileged than the tenant it serves. NVIDIA scores it local with required user interaction: someone must run the optimizer on the hostile file, which is exactly what an optimization pipeline does by design.

Who can reach it

Local - whoever runs Model-Optimizer must be induced to process an attacker-supplied model file or checkpoint. No authentication to NVIDIA infrastructure is involved; the trust boundary is the model artifact itself.

What to do

Upgrade Model-Optimizer to the version listed in NVIDIA's advisory for bulletin 5903 and rebuild any container image or pipeline that pins it. No node reboot or firmware work is needed. Because the exposure is the artifact, also run optimization in a sandboxed, non-privileged job with no credentials mounted, and prefer safetensors-style formats over pickle-backed checkpoints for anything from outside your own training runs.

References

Related entries

All AI/ML frameworks & serving entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.