Python libraries used in top AI and ML tools hacked – Nvidia, Salesforce and other libraries are all at risk


  • Palo Alto found critical bugs in the AI/ML libraries NeMo, Uni2TS and FlexTok
  • Vulnerabilities allowed arbitrary code execution via malicious model metadata
  • All fixed by mid-2025; no utilization observed in December 2025

Security researchers from Palo Alto Networks have discovered vulnerabilities used in some top artificial intelligence (AI) and machine learning (ML) tools that, if exploited, could allow threat actors to execute malicious code on measurement endpoints remotely.

In a security advisory, the researchers said that around April 2025, they discovered bugs in three open source Python libraries published by Apple, Salesforce and NVIDIA on their GitHub repositories.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top