Junglewise Threat Intelligence

CVE-2026-24252: NVIDIA NeMo OS command injection on Linux

CVE-2026-24252 · Severity: high · CVSS 7.8 · Published 2026-07-27

Technologies: Nvidia NeMo Framework. Vendors: Nvidia.

Executive brief

NVIDIA NeMo, a framework used by developers to build and deploy generative AI models, contains a security flaw on Linux systems. A local attacker with basic access to the system could exploit this vulnerability to run unauthorized commands. This could lead to the theft of sensitive AI training data, unauthorized system changes, or full control over the affected server.

Technical details

An OS command injection vulnerability (CWE-78) exists in NVIDIA NeMo Framework for Linux in versions 0.0 through 2.7.2. The flaw allows a local attacker with low privileges to inject and execute arbitrary shell commands on the host system without user interaction. Successful exploitation can result in full system compromise, including unauthorized code execution, privilege escalation, and sensitive information disclosure. Users are advised to review NVIDIA's security advisory for specific patching or mitigation instructions.

Affected products

  • NVIDIA NeMo Framework 0.0 to 2.7.2

Timeline

  • 2026-07-27: advisory: NVIDIA published the security advisory and CVE details.

References

Related threats