Deserialization of Untrusted Data in NVIDIA Nemo Framework - CVE-2026-24157
Published: May 18, 2026
NVIDIA Nemo Framework
Detailed vulnerability description
The vulnerability allows a local user to execute arbitrary code.
The vulnerability exists due to deserialization of untrusted data in checkpoint loading when loading a crafted checkpoint. A local user can load a specially crafted checkpoint to execute arbitrary code.
The advisory states that successful exploitation may also lead to information disclosure, data tampering, and escalation of privileges.