logo

NVIDIA NeMo Framework Flaw Enables Code Injection and Privilege Escalation

ID: ee2db7e5-88d8-5feb-bb4e-b916c7ab7836

STIX ID: report--ee2db7e5-88d8-5feb-bb4e-b916c7ab7836

Feed Name: Cyber Press

Threat Score
65/100

Date Published: 2025-11-14

Date Updated: 2026-04-19

Author: AnuPriya

...
...

**NVIDIA NeMo Framework vulnerabilities (CVE-2025-23361, CVE-2025-33178):** Two high-severity (CVSS 7.8) flaws in NeMo versions before 2.5.0 allow local, low-privileged attackers to execute arbitrary code, escalate privileges, and tamper with or disclose data; NVIDIA advises immediate update to NeMo 2.5.0 via GitHub or PyPI.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.