Next upHack for Humanity: San Francisco (powered by Google Gemini)
News

NVIDIA patches three high-severity flaws in its NeMo AI framework, urges upgrade to 2.7.3

All three vulnerabilities carry a CVSS score of 7.8 and need only local low-privilege access with no user interaction, NVIDIA said.

Dmytro Spodarets
Jun 17, 2026 · 1 min read

NVIDIA on June 16, 2026 disclosed three high-severity vulnerabilities in the NVIDIA NeMo Framework, its open-source platform for building and deploying large language models, and released version 2.7.3 to fix them. Each carries a CVSS v3.1 base score of 7.8.

The flaws are notable because all three need only local access with low privileges and no user interaction, which NVIDIA said makes them especially dangerous in multi-tenant AI development and containerized cloud GPU environments where many workloads share hardware.

The first, CVE-2026-24252, is an OS command injection issue affecting NeMo on Linux that lets a local low-privilege attacker inject arbitrary operating-system commands, potentially leading to code execution and privilege escalation. CVE-2026-24155, a code injection flaw, affects all platforms and likewise allows arbitrary code execution and privilege escalation. CVE-2026-24228 stems from deserialization of untrusted data, such as Python pickle, on Linux and enables arbitrary code execution at runtime.

The vulnerabilities affect NeMo Framework versions 0.0 through 2.7.2 on all supported platforms, and the security bulletin directs users to upgrade to version 2.7.3 or later. NVIDIA credited Moomi Chen for reporting two of the issues and Tyler Zars of the TrendAI Zero Day Initiative for the deserialization flaw.

NVIDIA's bulletin reports no known exploitation, and exploitation requires local access. The company did not say how many deployments run the affected versions.


Dmytro Spodarets
Dmytro Spodarets
Founder & Editor-in-Chief

Founder and Chief Editor of Data Phoenix — a San Francisco Bay Area media and education platform focused on AI and Data.

More news