NVIDIA NeMo Framework Remote Code Execution Vulnerability

Vulnerability

A remote code execution vulnerability has been identified in NVIDIA NeMo Framework, affecting all versions prior to 2.6.2. This vulnerability arises from the deserialization of untrusted data, which could be exploited to execute arbitrary code. Successful exploitation may also lead to unauthorized privilege escalation, disclosure of sensitive information, and unauthorized modification of data.

Impact

Exploitation of this vulnerability allows for remote code execution, with potential consequences including unauthorized access to elevated privileges, leakage of confidential information, and unauthorized alterations to data.

Remediation

Users are advised to update to version 2.6.2 or later. The updated version is available on the NVIDIA GitHub repository and through the Python Package Index (PyPI).

Added: Mar 24, 2026, 9:30 PM
Updated: Mar 24, 2026, 9:30 PM

Vulnerability Rating

Custom Algorithm
spread
2.4
impact
5.0
exploitability
2.7
remediation
7.7
relevance
4.6
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.