CVE-2026-65178: High severity Nvidia NeMo vulnerability
Published Sep 22, 2026
·Updated
NVIDIA NeMo contains a vulnerability in its dataset-loading workflow where a maliciously crafted modelconfig.yaml can inject unsafe parameters. A successful exploit of this vulnerability may lead to code execution, data tampering, denial of service, and information disclosure.
Affected Software
1 affected component
Nvidia NeMo
Event History
Sep 22, 2026
CVE Published
via MITRE·02:03 PM
Data Sourced
via MITRE·02:03 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What level of access does an attacker need to exploit this issue?
The attacker needs local access and low privileges on the affected system. The CVSS vector indicates that exploitation does not require network access or user interaction.
2
What are the potential consequences of successful exploitation?
Successful exploitation may allow code execution, data tampering, denial of service, and information disclosure. The vulnerability has high impacts on confidentiality, integrity, and availability.