Python libraries used in major AI and ML tools hacked – Nvidia, Salesforce and other libraries are all at risk


  • Palo Alto found critical flaws in AI/ML libraries NeMo, Uni2TS and FlexTok
  • Vulnerabilities allowed arbitrary code execution via malicious model metadata
  • All fixed by mid-2025; no exploitation observed in December 2025

Security researchers at Palo Alto Networks have discovered vulnerabilities used in some leading artificial intelligence (AI) and machine learning (ML) tools that, if abused, could allow malicious actors to remotely execute malicious code on target endpoints.

In a security advisory, the researchers said that around April 2025, they discovered bugs in three open source Python libraries released by Apple, Salesforce and NVIDIA, on their GitHub repositories.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top