Executive brief
NVIDIA NeMo Speech is a framework for building speech recognition and synthesis applications. Malicious input can trigger code injection, potentially allowing an attacker to execute arbitrary code, access sensitive data, or modify stored information on affected systems.
Technical details
The vulnerability is a code injection flaw in NVIDIA NeMo Speech that can be triggered via malicious input on all supported platforms. Exploitation allows remote code execution, information disclosure, and data tampering without requiring authentication or special privileges. Patches are expected from NVIDIA through their security bulletin process.
Affected products
- NVIDIA NeMo Speech all platforms
Timeline
- 2026-09-22: disclosed