Deserialization of Untrusted Data in NVIDIA Nemo Framework - CVE-2026-24157

 

Deserialization of Untrusted Data in NVIDIA Nemo Framework - CVE-2026-24157

Published: May 18, 2026


Vulnerability identifier: #VU131721
CSH Severity: Low
CVSS v4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-24157
CWE-ID: CWE-502
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to execute arbitrary code.

The vulnerability exists due to deserialization of untrusted data in checkpoint loading when loading a crafted checkpoint. A local user can load a specially crafted checkpoint to execute arbitrary code.

The advisory states that successful exploitation may also lead to information disclosure, data tampering, and escalation of privileges.


Affected software

NVIDIA Nemo Framework

How to mitigate CVE-2026-24157

Install security update from vendor's website.

NVIDIA Nemo Framework - update to 2.6.2

External References

Related Security Bulletins