GPU VulnDB

Database/AI/ML frameworks & serving

NVIDIA NeMo: a crafted model_config.yaml injects unsafe parameters into dataset loading

CVSS 7.8CVE-2026-65178AI/ML frameworks & servingcurated

Impact

A maliciously crafted model_config.yaml can inject unsafe parameters into NeMo's dataset-loading workflow, leading to code execution, data tampering, denial of service or information disclosure in the job that reads it. This is a separate flaw from the TabularTokenizer pickle issue in the same bulletin - the entry point is the YAML config, not a .pkl - and NVIDIA scores it local with low privileges required (7.8), so the attacker already has a foothold that can write or supply the config a job consumes. On a shared cluster, that is any tenant who can drop a config into a shared experiment directory or a pipeline that accepts user-provided model configs; the payoff is running code as the training job, next to its GPUs and credentials.

Who can reach it

Local, authenticated: a user or process able to supply or modify the model_config.yaml that a NeMo job loads - a shared filesystem path, a pipeline parameter, or a downloaded model bundle. No user interaction is needed once the config is in place.

What to do

Upgrade NeMo to the fixed version in NVIDIA bulletin 2026/5885 and restart the jobs and services that use it - a package update and process restart, no node maintenance. In the interim, make config files come only from a trusted, write-controlled location and do not let tenants hand arbitrary model_config.yaml files to shared training pipelines.

References

Related entries

All AI/ML frameworks & serving entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.