Junglewise Threat Intelligence

CVE-2026-24228: NVIDIA NeMo Framework deserialization of untrusted data on Linux

CVE-2026-24228 · Severity: high · CVSS 7.8 · Published 2026-06-16

Technologies: Nvidia NeMo Framework. Vendors: Nvidia.

Executive brief

NVIDIA NeMo Framework, a toolkit used for building and deploying generative AI models, contains a security vulnerability on Linux systems. An attacker with local access to the system could exploit this flaw to take control of the environment, access sensitive data, or disrupt operations. This could lead to unauthorized access to proprietary AI models or corporate data stored on the affected server.

Technical details

A deserialization of untrusted data vulnerability (CWE-502) exists in the NVIDIA NeMo Framework for Linux. The flaw allows a local attacker with low privileges to provide malicious input that, when processed by the framework, executes arbitrary code. According to the CVSS vector, the attack requires no user interaction and has a low complexity. Successful exploitation can result in a complete compromise of confidentiality, integrity, and availability, including privilege escalation and information disclosure. Users should refer to NVIDIA advisory 5839 for specific version fixes.

Affected products

  • NVIDIA NeMo Framework Linux versions

Timeline

  • 2026-06-16: disclosed
  • 2026-06-16: advisory

References

Related threats