Database/AI/ML frameworks & serving
NVIDIA NeMo: TabularTokenizer unpickles an attacker-supplied .pkl file, giving code execution
Impact
The TabularTokenizer class passes an untrusted, attacker-controlled .pkl file to pickle.load() without validation, so anyone who can choose the tokenizer artifact a NeMo job loads gets arbitrary code execution inside that job. On a GPU fleet that means execution as the training or inference process, on a node with the GPUs, the driver and whatever credentials the job carries - model weights, dataset buckets, cluster tokens. NVIDIA scores it 8.8 network with user interaction, which matches the usual path: an operator or pipeline pulls a tokenizer or checkpoint from a model hub or a shared artifact store and runs it. The impact list also covers data tampering, denial of service and information disclosure.
Who can reach it
Anyone who can place or substitute the .pkl tokenizer artifact that a NeMo job loads - a public or shared model registry, an object-store path, or a user-supplied upload. No prior authentication to the cluster is required if the artifact source is open; a user has to be induced to load the file.
What to do
Upgrade NeMo to the fixed version listed in NVIDIA bulletin 2026/5885 and restart the affected training and inference services; no node reboot or firmware work is involved. Pending that, treat tokenizer and checkpoint pickles as executable content: pin artifacts to hashes from a registry you control, and block jobs from pulling .pkl files off untrusted hubs.
References
Related entries
- Hugging Face peft: CorDA and LoRA-GA load cache files with unsafe torch.load, giving code executionCVE-2026-71281 · Hugging Face peft - LoRA-GA and CorDA initialization (torch.load without weights_only)High
- ChromaDB (Rust): Missing authorization validationCVE-2026-8828 · ChromaDB (Rust)High
- LangBot: debug WebSocket on 0.0.0.0:5401 accepts plugin registration with no key setCVE-2026-90938 · LangBot plugin runtime (langbot_plugin debug WebSocket on 0.0.0.0:5401)High
- SGLang: unauthenticated PUT /route poisons the KV transfer routing table in disaggregated modeCVE-2026-92972 · SGLang prefill bootstrap service (unauthenticated PUT /route)High
- vLLM OpenAI-compatible server (qwen3_coder tool-call parser): Code execution inside the serving process, which on a GPUNCVD-2025-017-vllm-openai-compatible-server-qw · vLLM OpenAI-compatible server (qwen3_coder tool-call parser)High
- vLLM (multimodal prompt embeddings, sparse tensor validation): This is the advisory saying the earlier fix did notNCVD-2026-043-vllm-multimodal-prompt-embedding · vLLM (multimodal prompt embeddings, sparse tensor validation)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.