Database/AI/ML frameworks & serving
NVIDIA NeMo: a crafted model_config.yaml injects unsafe parameters into dataset loading
Impact
A maliciously crafted model_config.yaml can inject unsafe parameters into NeMo's dataset-loading workflow, leading to code execution, data tampering, denial of service or information disclosure in the job that reads it. This is a separate flaw from the TabularTokenizer pickle issue in the same bulletin - the entry point is the YAML config, not a .pkl - and NVIDIA scores it local with low privileges required (7.8), so the attacker already has a foothold that can write or supply the config a job consumes. On a shared cluster, that is any tenant who can drop a config into a shared experiment directory or a pipeline that accepts user-provided model configs; the payoff is running code as the training job, next to its GPUs and credentials.
Who can reach it
Local, authenticated: a user or process able to supply or modify the model_config.yaml that a NeMo job loads - a shared filesystem path, a pipeline parameter, or a downloaded model bundle. No user interaction is needed once the config is in place.
What to do
Upgrade NeMo to the fixed version in NVIDIA bulletin 2026/5885 and restart the jobs and services that use it - a package update and process restart, no node maintenance. In the interim, make config files come only from a trusted, write-controlled location and do not let tenants hand arbitrary model_config.yaml files to shared training pipelines.
References
Related entries
- PyTorch (flatbuffer model parsing, torch::load / parse_and_initialize_mobile_module): MALICIOUS MODEL FILE TO MEMORYNCVD-2025-019-pytorch-flatbuffer-model-parsing · PyTorch (flatbuffer model parsing, torch::load / parse_and_initialize_mobile_module)High
- LangChain (Web Research Retriever): SSRFCVE-2024-3095 · LangChain (Web Research Retriever)High
- LangGraph MongoDB checkpoint and store: filter dicts allow MQL operator injection across tenantsCVE-2026-55253 · langgraph-checkpoint-mongodb / langgraph-store-mongodb (MongoDBSaver.list, MongoDBStore.search filters)High
- Kedro-Datasets PyTorchDataset: torch.load without weights_only executes code from .pt filesCVE-2026-62997 · kedro-datasets PyTorchDataset (kedro_datasets_experimental.pytorch)High
- SitemapLoader: nested sitemap entries skip restrict_to_same_domain, giving readable SSRFCVE-2026-72848 · langchain-community SitemapLoader (nested sitemap index entries)High
- JupyterLab: missing await skips extension allowlist check for direct PyPIExtensionManager callersCVE-2026-73626 · JupyterLab PyPIExtensionManager.install() (extension allowlist/blocklist enforcement)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.