Executive brief
NVIDIA NeMo Speech is a machine learning platform for building speech AI applications. A vulnerability in its speech data explorer component allows attackers to execute arbitrary code remotely by providing malicious data, potentially leading to system compromise, data theft, and unauthorized access to sensitive information.
Technical details
The vulnerability exists in the speech data explorer component of NVIDIA NeMo Speech and can be triggered by specially crafted malicious data, leading to remote code execution. The attack appears to require crafted input but the specific attack vector and authentication requirements are not detailed in available references. Successful exploitation grants the attacker code execution with potential privilege escalation, information disclosure, and data tampering capabilities.
Affected products
- NVIDIA NeMo Speech all platforms
Timeline
- 2026-09-22: disclosed