Python Libraries Used in Major AI and Machine Learning Tools Hacked: Nvidia, Salesforce, and Other Libraries at Risk



  • Palo Alto found critical flaws in AI/ML libraries NeMo, Uni2TS and FlexTok
  • Vulnerabilities allowed arbitrary code execution via malicious model metadata
  • All patched by mid-2025; no exploitation was observed after December 2025

Security researchers at Palo Alto Networks have discovered vulnerabilities used in some leading artificial intelligence (AI) and machine learning (ML) tools that, if abused, could allow threat actors to execute malicious code on target endpoints, remotely.

In a security advisory, researchers said that around April 2025 they discovered bugs in three open source Python libraries published by Apple, Salesforce and NVIDIA in their GitHub repositories.



Leave a Comment

Your email address will not be published. Required fields are marked *