GPU VulnDB

Database/AI/ML frameworks & serving

NVIDIA NeMo: TabularTokenizer unpickles an attacker-supplied .pkl file, giving code execution

CVSS 8.8CVE-2026-65179AI/ML frameworks & servingcurated

Impact

The TabularTokenizer class passes an untrusted, attacker-controlled .pkl file to pickle.load() without validation, so anyone who can choose the tokenizer artifact a NeMo job loads gets arbitrary code execution inside that job. On a GPU fleet that means execution as the training or inference process, on a node with the GPUs, the driver and whatever credentials the job carries - model weights, dataset buckets, cluster tokens. NVIDIA scores it 8.8 network with user interaction, which matches the usual path: an operator or pipeline pulls a tokenizer or checkpoint from a model hub or a shared artifact store and runs it. The impact list also covers data tampering, denial of service and information disclosure.

Who can reach it

Anyone who can place or substitute the .pkl tokenizer artifact that a NeMo job loads - a public or shared model registry, an object-store path, or a user-supplied upload. No prior authentication to the cluster is required if the artifact source is open; a user has to be induced to load the file.

What to do

Upgrade NeMo to the fixed version listed in NVIDIA bulletin 2026/5885 and restart the affected training and inference services; no node reboot or firmware work is involved. Pending that, treat tokenizer and checkpoint pickles as executable content: pin artifacts to hashes from a registry you control, and block jobs from pulling .pkl files off untrusted hubs.

References

Related entries

All AI/ML frameworks & serving entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.