NVIDIA NeMo Framework Flaw Enables Code Injection and Privilege Escalation
ID: ee2db7e5-88d8-5feb-bb4e-b916c7ab7836
STIX ID: report--ee2db7e5-88d8-5feb-bb4e-b916c7ab7836
Feed Name: Cyber Press
Threat Score
**NVIDIA NeMo Framework vulnerabilities (CVE-2025-23361, CVE-2025-33178):** Two high-severity (CVSS 7.8) flaws in NeMo versions before 2.5.0 allow local, low-privileged attackers to execute arbitrary code, escalate privileges, and tamper with or disclose data; NVIDIA advises immediate update to NeMo 2.5.0 via GitHub or PyPI.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
