Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-m4jw-wgmf-889x | NVIDIA NeMo Framework contains an RCE vulnerability in checkpoint loading |
Wed, 01 Apr 2026 02:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Remote Code Execution in NVIDIA NeMo Framework Checkpoint Loading |
Tue, 31 Mar 2026 03:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Nvidia nemo
|
|
| CPEs | cpe:2.3:a:nvidia:nemo:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Nvidia nemo
|
Wed, 25 Mar 2026 22:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Remote Code Execution in NVIDIA NeMo Framework Checkpoint Loading |
Wed, 25 Mar 2026 12:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Nvidia
Nvidia nemo Framework |
|
| Vendors & Products |
Nvidia
Nvidia nemo Framework |
Tue, 24 Mar 2026 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 24 Mar 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | NVIDIA NeMo Framework contains a vulnerability in checkpoint loading where an attacker could cause remote code execution. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, information disclosure and data tampering. | |
| Weaknesses | CWE-502 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: nvidia
Published:
Updated: 2026-03-25T03:56:16.911Z
Reserved: 2026-01-21T19:09:29.851Z
Link: CVE-2026-24157
Updated: 2026-03-24T20:53:26.652Z
Status : Analyzed
Published: 2026-03-24T21:16:27.823
Modified: 2026-03-31T01:29:58.490
Link: CVE-2026-24157
No data.
OpenCVE Enrichment
Updated: 2026-03-31T20:09:20Z
Github GHSA