Executive brief
NVIDIA NVTabular, a feature engineering and preprocessing library for deep learning, contains a security flaw in how it processes data. An attacker with local access to a system could exploit this vulnerability to run unauthorized commands, modify sensitive data, or view private information. This could lead to a full compromise of the machine where the data processing is occurring.
Technical details
A deserialization vulnerability (CWE-502) exists in NVIDIA NVTabular due to the improper handling of untrusted data during object reconstruction. An attacker with local access and low privileges can exploit this flaw by providing a specially crafted serialized object. If successfully exploited, the vulnerability allows for arbitrary code execution in the context of the application, as well as unauthorized data modification and information disclosure. The attack vector is local (AV:L), requiring the attacker to have a foothold on the system where NVTabular is running.
Affected products
- NVIDIA NVTabular
Timeline
- 2026-06-02: disclosed
- 2026-06-02: advisory: NVD published the CVE record based on NVIDIA's disclosure.