ZDI-26-410: NVIDIA NeMo Framework Deserialization of Untrusted Data Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on affected installations of NVIDIA NeMo Framework. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-24228.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-26-410?
ZDI-26-410 has a CVSS rating of 7.8, indicating a high severity risk.
How do I fix ZDI-26-410?
To fix ZDI-26-410, update the NVIDIA NeMo Framework to the latest version provided by NVIDIA.
What type of vulnerability is ZDI-26-410?
ZDI-26-410 is a deserialization of untrusted data vulnerability that can lead to remote code execution.
What requirements are needed to exploit ZDI-26-410?
Exploitation of ZDI-26-410 requires user interaction, specifically by visiting a malicious page or opening a malicious file.
Which software is affected by ZDI-26-410?
ZDI-26-410 affects installations of the NVIDIA NeMo Framework.