Database/AI/ML frameworks & serving
NVIDIA Model-Optimizer: deserialization of untrusted data leads to code execution
Impact
Model-Optimizer is the quantization and sparsification toolchain teams run before serving a model on TensorRT or Triton. It deserializes untrusted input, so a crafted checkpoint or artifact handed to the optimizer executes code with the privileges of the user running it, and can also tamper with the resulting model or leak data from the job. On a shared GPU fleet the realistic path is a model pulled from a hub or supplied by a tenant and then optimized by a pipeline account that is often more privileged than the tenant it serves. NVIDIA scores it local with required user interaction: someone must run the optimizer on the hostile file, which is exactly what an optimization pipeline does by design.
Who can reach it
Local - whoever runs Model-Optimizer must be induced to process an attacker-supplied model file or checkpoint. No authentication to NVIDIA infrastructure is involved; the trust boundary is the model artifact itself.
What to do
Upgrade Model-Optimizer to the version listed in NVIDIA's advisory for bulletin 5903 and rebuild any container image or pipeline that pins it. No node reboot or firmware work is needed. Because the exposure is the artifact, also run optimization in a sandboxed, non-privileged job with no credentials mounted, and prefer safetensors-style formats over pickle-backed checkpoints for anything from outside your own training runs.
References
Related entries
- NVIDIA NeMo: a crafted model_config.yaml injects unsafe parameters into dataset loadingCVE-2026-65178 · NVIDIA NeMo (dataset-loading workflow, model_config.yaml parameter injection)High
- PyTorch (flatbuffer model parsing, torch::load / parse_and_initialize_mobile_module): MALICIOUS MODEL FILE TO MEMORYNCVD-2025-019-pytorch-flatbuffer-model-parsing · PyTorch (flatbuffer model parsing, torch::load / parse_and_initialize_mobile_module)High
- LangChain (Web Research Retriever): SSRFCVE-2024-3095 · LangChain (Web Research Retriever)High
- LangGraph MongoDB checkpoint and store: filter dicts allow MQL operator injection across tenantsCVE-2026-55253 · langgraph-checkpoint-mongodb / langgraph-store-mongodb (MongoDBSaver.list, MongoDBStore.search filters)High
- Kedro-Datasets PyTorchDataset: torch.load without weights_only executes code from .pt filesCVE-2026-62997 · kedro-datasets PyTorchDataset (kedro_datasets_experimental.pytorch)High
- SitemapLoader: nested sitemap entries skip restrict_to_same_domain, giving readable SSRFCVE-2026-72848 · langchain-community SitemapLoader (nested sitemap index entries)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.