Description
NVIDIA NeMo Speech for all platforms contains a vulnerability where malicious input created by an attacker could cause a code injection. A successful exploit of this vulnerability might lead to code execution, information disclosure, and data tampering.
Published: 2026-09-22
Score: 7.8 High
EPSS: n/a
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

The vulnerability in NVIDIA NeMo Speech allows maliciously crafted input to trigger a code injection that can lead to arbitrary code execution, information disclosure, or data tampering within the affected system. The weakness lies in insufficient validation of speech input, enabling the injection of executable commands. This flaw could compromise the confidentiality, integrity, and availability of the application or the host system if exploited.

Affected Systems

All platforms running NVIDIA NeMo Speech are affected. Specific version information is not provided in the available data.

Risk and Exploitability

The CVSS score of 7.8 indicates a high severity. EPSS data is unavailable, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is the delivery of specially crafted speech input to an exposed API or processing endpoint, which may be reachable remotely or locally depending on deployment. A successful exploitation would give the attacker the ability to execute arbitrary commands with the privileges of the NeMo Speech process.

Generated by OpenCVE AI on September 22, 2026 at 16:34 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest NeMo Speech update or patch released by NVIDIA (see the GitHub product‑security repository for the update).
  • Override or sanitize all input streams to the NeMo Speech service by validating that the input conforms strictly to allowable audio formats and length limits.
  • Restrict the execution privileges of the NeMo Speech process, ensuring it runs with the minimum required permissions and is monitored for unexpected command execution.

Generated by OpenCVE AI on September 22, 2026 at 16:34 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 22 Sep 2026 19:45:00 +0000

Type Values Removed Values Added
First Time appeared Nvidia
Nvidia nemo Speech
Vendors & Products Nvidia
Nvidia nemo Speech

Tue, 22 Sep 2026 17:00:00 +0000

Type Values Removed Values Added
Title Code Injection Vulnerability in NVIDIA NeMo Speech

Tue, 22 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Description NVIDIA NeMo Speech for all platforms contains a vulnerability where malicious input created by an attacker could cause a code injection. A successful exploit of this vulnerability might lead to code execution, information disclosure, and data tampering.
Weaknesses CWE-77
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Nvidia Nemo Speech
cve-icon MITRE

Status: PUBLISHED

Assigner: nvidia

Published:

Updated: 2026-09-22T15:29:40.707Z

Reserved: 2026-07-21T17:12:30.490Z

Link: CVE-2026-65111

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-22T15:17:11.253

Modified: 2026-09-22T19:37:36.747

Link: CVE-2026-65111

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-22T19:14:58Z

Weaknesses
  • CWE-77

    Improper Neutralization of Special Elements used in a Command ('Command Injection')