Junglewise Threat Intelligence

CVE-2026-24217: NVIDIA BioNeMo Core path traversal via malicious file loading

CVE-2026-24217 · Severity: high · CVSS 8.8 · Published 2026-05-20

Vendors: Nvidia.

Executive brief

NVIDIA BioNeMo Core, a framework used for generative AI in drug discovery, contains a security flaw that can be triggered when a user loads a specially crafted file. If exploited, this could allow an attacker to gain unauthorized access to sensitive data, disrupt operations, or execute malicious code on the system. This poses a significant risk to the integrity of research data and the availability of AI development environments.

Technical details

A path traversal vulnerability (CWE-29) exists in NVIDIA BioNeMo Core for Linux. The flaw is triggered when the application processes a maliciously crafted file, allowing an attacker to bypass directory restrictions. The attack vector is network-based and requires user interaction (UI:R), such as a user being tricked into loading the malicious file. Successful exploitation can result in full compromise of the CIA triad (Confidentiality, Integrity, and Availability), including remote code execution (RCE), information disclosure, and denial of service. NVIDIA has assigned a CVSS v3.1 base score of 8.8.

Affected products

  • NVIDIA BioNeMo Core Linux version

Timeline

  • 2026-05-20: disclosed: Initial publication of CVE-2026-24217
  • 2026-05-20: advisory: NVIDIA security advisory published

References