Executive brief
NVIDIA BioNeMo, a generative AI platform for drug discovery, contains a security flaw that could allow an attacker to execute malicious code. By tricking a user into processing a specially crafted file, an attacker could gain unauthorized access to sensitive research data, disrupt operations, or tamper with scientific results. This vulnerability poses a significant risk to organizations using the framework for pharmaceutical and biological research.
Technical details
A deserialization of untrusted data vulnerability (CWE-502) exists in the NVIDIA BioNeMo Framework. The flaw allows an attacker to provide malicious input that, when processed by the framework, triggers the execution of arbitrary code or causes a denial of service. While the CNA (NVIDIA) lists a local attack vector requiring user interaction (AV:L/UI:R), NIST's initial analysis suggests a network-based vector with low privileges (AV:N/PR:L). Successful exploitation grants the attacker the ability to disclose information, tamper with data, or fully compromise the host system. The issue is addressed in versions including or following commit e5e58c8.
Affected products
- NVIDIA BioNeMo Framework All versions prior to commit e5e58c8
Timeline
- 2026-03-31: disclosed
- 2026-03-31: advisory