Junglewise Threat Intelligence

CVE-2025-33255: NVIDIA TRT-LLM unsafe deserialization in MPI server

CVE-2025-33255 · Severity: high · CVSS 7.5 · Published 2026-05-20

Technologies: Nvidia TRT-LLM. Vendors: Nvidia.

Executive brief

NVIDIA TRT-LLM, a library used to accelerate the performance of Large Language Models, contains a security vulnerability in its MPI server component. An attacker with high-level local access could exploit this flaw to execute unauthorized commands or disrupt AI services. This could lead to a complete system takeover, data theft, or permanent damage to the integrity of the AI models being served.

Technical details

A vulnerability exists in the MPI (Message Passing Interface) server component of NVIDIA TRT-LLM due to the unsafe deserialization of untrusted data (CWE-502). The flaw requires the attacker to have local access with high privileges and involves a high level of complexity to exploit. If successfully exploited, the attacker can achieve arbitrary code execution with the potential to escape the immediate environment (Scope: Changed), leading to full compromise of confidentiality, integrity, and availability. Users are advised to refer to NVIDIA advisory a_id/5805 for specific patching instructions.

Affected products

  • NVIDIA TRT-LLM All platforms

Timeline

  • 2026-05-20: disclosed: Initial public disclosure by NVIDIA

References

Related threats