Executive brief
NVIDIA NeMo, a framework used by developers to build and deploy generative AI models, contains a security flaw that allows for code injection. An attacker with local access to a system running this framework could execute unauthorized commands, potentially leading to the theft of sensitive data, unauthorized system changes, or full control over the affected environment. This could compromise the integrity of AI models and the confidentiality of the data they process.
Technical details
A code injection vulnerability (CWE-94) exists in the NVIDIA NeMo Framework across all supported platforms. The flaw allows an attacker with local access and low privileges to inject and execute arbitrary code within the context of the framework. According to the CVSS vector, the attack requires no user interaction and has a high impact on confidentiality, integrity, and availability. Successful exploitation could enable an attacker to escalate privileges, disclose sensitive information, or tamper with data and AI model integrity. Users are advised to refer to NVIDIA advisory 5839 for specific version impacts and patching instructions.
Affected products
- NVIDIA NeMo Framework All platforms
Timeline
- 2026-06-16: disclosed: Initial disclosure by NVIDIA and NVD publication