Executive brief
NVIDIA NeMo is a framework for building speech and language AI models. The TabularTokenizer component unsafely deserializes untrusted pickle files, allowing an attacker to execute arbitrary code, modify data, disrupt service, or steal information if a malicious .pkl file is processed.
Technical details
The vulnerability exists in the TabularTokenizer class, which calls pickle.load() on user-supplied .pkl files without validation or signing. An attacker can craft a malicious pickle file that executes arbitrary Python code during deserialization. Exploitation requires the victim to process an attacker-controlled .pkl file, leading to remote code execution with the privileges of the NeMo process.
Affected products
- NVIDIA NeMo <UNKNOWN>
Timeline
- 2026-09-22: disclosed