Junglewise Threat Intelligence

CVE-2026-24216: NVIDIA BioNeMo deserialization of untrusted data in Linux

CVE-2026-24216 · Severity: high · CVSS 7.8 · Published 2026-05-20

Vendors: Nvidia.

Executive brief

NVIDIA BioNeMo, a generative AI platform for drug discovery, contains a security vulnerability in how it processes data. An attacker could exploit this by tricking a user into opening a specially crafted file, potentially allowing the attacker to take control of the system, steal sensitive research data, or disrupt operations. This issue primarily affects users running the software on Linux environments.

Technical details

A deserialization of untrusted data vulnerability (CWE-502) exists in NVIDIA BioNeMo for Linux. The flaw occurs when the application processes maliciously crafted serialized data without sufficient validation. An attacker can exploit this by convincing a local user to interact with a malicious file (User Interaction required). Successful exploitation can lead to arbitrary code execution in the context of the application, information disclosure, or a denial of service state. The vulnerability is tracked as CVE-2026-24216 and has a CVSS 3.1 base score of 7.8.

Affected products

  • NVIDIA BioNeMo Linux versions

Timeline

  • 2026-05-20: disclosed
  • 2026-05-20: advisory

References