Python libraries used in top AI and ML tools hacked – Nvidia, Salesforce and other libraries all at risk



  • Palo Alto found critical flaws in AI/ML libraries NeMo, Uni2TS, and FlexTok
  • Vulnerabilities allowed arbitrary code execution via malicious model metadata
  • All patched by mid-2025; no exploitation observed as of December 2025

Security researchers from Palo Alto Networks have discovered vulnerabilities used in some top Artificial Intelligence (AI) and machine Learning (ML) tools which, if abused, could allow threat actors to execute malicious code on target endpoints, remotely.

In a security advisory, the researchers said that around April 2025, they discovered bugs in three open source Python libraries published by Apple, Salesforce, and NVIDIA, on their GitHub repositories.


https://cdn.mos.cms.futurecdn.net/pJjsnhgKdD782c5SBEneTW-970-80.jpg



Source link

Latest articles

spot_imgspot_img

Related articles

spot_imgspot_img