CVE-2025-33228
published 2026-01-20CVE-2025-33228: NVIDIA Nsight Systems contains a vulnerability in the gfx_hotspot recipe, where an attacker could cause an OS command injection by supplying a malicious string…
PriorityP341high7.3CVSS 3.1
AVLACLPRLUIRSUCHIHAH
EPSS
1.19%
64.2th percentile
NVIDIA Nsight Systems contains a vulnerability in the gfx_hotspot recipe, where an attacker could cause an OS command injection by supplying a malicious string to the process_nsys_rep_cli.py script if the script is invoked manually. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, denial of service, and information disclosure.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | nvidia-cuda-toolkit | — | — |
| nvidia | cuda_toolkit | < 13.1.0 | 13.1.0 |
| nvidia | cuda_toolkit | — | — |
CVSS provenance
nvdv3.17.3HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
osv7.3HIGH
vendor_debian7.3HIGH
vendor_redhat7.3HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-p5c4-pcw7-pqff: NVIDIA Nsight Systems contains a vulnerability in the gfx_hotspot recipe, where an attacker could cause an OS command injection by supplying a malicio
ghsa_unreviewed·2026-01-20
CVE-2025-33228 [HIGH] CWE-78 GHSA-p5c4-pcw7-pqff: NVIDIA Nsight Systems contains a vulnerability in the gfx_hotspot recipe, where an attacker could cause an OS command injection by supplying a malicio
NVIDIA Nsight Systems contains a vulnerability in the gfx_hotspot recipe, where an attacker could cause an OS command injection by supplying a malicious string to the process_nsys_rep_cli.py script if the script is invoked manually. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, denial of service, and information disclosure.
OSV
CVE-2025-33228: NVIDIA Nsight Systems contains a vulnerability in the gfx_hotspot recipe, where an attacker could cause an OS command injection by supplying a malicio
osv·2026-01-20·CVSS 7.3
CVE-2025-33228 [HIGH] CVE-2025-33228: NVIDIA Nsight Systems contains a vulnerability in the gfx_hotspot recipe, where an attacker could cause an OS command injection by supplying a malicio
NVIDIA Nsight Systems contains a vulnerability in the gfx_hotspot recipe, where an attacker could cause an OS command injection by supplying a malicious string to the process_nsys_rep_cli.py script if the script is invoked manually. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, denial of service, and information disclosure.
Red Hat
nsight-systems: Nsight Systems: Arbitrary code execution via OS command injection
vendor_redhat·2026-01-20·CVSS 7.3
CVE-2025-33228 [HIGH] CWE-78 nsight-systems: Nsight Systems: Arbitrary code execution via OS command injection
nsight-systems: Nsight Systems: Arbitrary code execution via OS command injection
NVIDIA Nsight Systems contains a vulnerability in the gfx_hotspot recipe, where an attacker could cause an OS command injection by supplying a malicious string to the process_nsys_rep_cli.py script if the script is invoked manually. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, denial of service, and information disclosure.
A flaw was found in NVIDIA Nsight Systems. This vulnerability allows a local attacker to achieve arbitrary code execution by manually invoking the process_nsys_rep_cli.py script with a malicious string. This OS command injection can lead to privilege escalation, data tampering, denial of service, and information disclos
Debian
CVE-2025-33228: nvidia-cuda-toolkit - NVIDIA Nsight Systems contains a vulnerability in the gfx_hotspot recipe, where ...
vendor_debian·2025·CVSS 7.3
CVE-2025-33228 [HIGH] CVE-2025-33228: nvidia-cuda-toolkit - NVIDIA Nsight Systems contains a vulnerability in the gfx_hotspot recipe, where ...
NVIDIA Nsight Systems contains a vulnerability in the gfx_hotspot recipe, where an attacker could cause an OS command injection by supplying a malicious string to the process_nsys_rep_cli.py script if the script is invoked manually. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, denial of service, and information disclosure.
Scope: local
bookworm: open
bullseye: open
forky: open
sid: open
trixie: open
No detection rules found.
No public exploits indexed.
Wiz
CVE-2025-33230 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 3.3
CVE-2025-33230 [LOW] CVE-2025-33230 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-33230 :
CUDA Toolkit vulnerability analysis and mitigation
NVIDIA Nsight Systems for Linux contains a vulnerability in the .run installer, where an attacker could cause an OS command injection by supplying a malicious string to the installation path. A successful exploit of this vulnerability might lead to escalation of privileges, code execution, data tampering, denial of service, and information disclosure.
Source : NVD
## 7.3
Score
Published January 20, 2026
Severity HIGH
CNA Score 7.3
Affected Technologies
CUDA Toolkit
Linux Debian
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 6.1
Exploitation Probability (EPSS) N/A
Affected packages and libraries
nvidia-cuda-tool
Wiz
CVE-2025-33228 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 3.3
CVE-2025-33228 [LOW] CVE-2025-33228 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-33228 :
CUDA Toolkit vulnerability analysis and mitigation
NVIDIA Nsight Systems contains a vulnerability in the gfx_hotspot recipe, where an attacker could cause an OS command injection by supplying a malicious string to the process_nsys_rep_cli.py script if the script is invoked manually. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, denial of service, and information disclosure.
Source : NVD
## 7.3
Score
Published January 20, 2026
Severity HIGH
CNA Score 7.3
Affected Technologies
CUDA Toolkit
Linux Debian
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 6.1
Exploitation Probability (EPSS) N/A
Affected
Wiz
CVE-2025-33231 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 3.3
CVE-2025-33231 [LOW] CVE-2025-33231 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-33231 :
CUDA Toolkit vulnerability analysis and mitigation
NVIDIA Nsight Systems for Windows contains a vulnerability in the application’s DLL loading mechanism where an attacker could cause an uncontrolled search path element by exploiting insecure DLL search paths. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, denial of service and information disclosure.
Source : NVD
## 6.7
Score
Published January 20, 2026
Severity MEDIUM
CNA Score 6.7
Affected Technologies
CUDA Toolkit
Linux Debian
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 4.9
Exploitation Probability (EPSS) N/A
Affected packages and libraries
Wiz
CVE-2025-33229 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 3.3
CVE-2025-33229 [LOW] CVE-2025-33229 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-33229 :
CUDA Toolkit vulnerability analysis and mitigation
NVIDIA Nsight Visual Studio for Windows contains a vulnerability in Nsight Monitor where an attacker can execute arbitrary code with the same privileges as the NVIDIA Nsight Visual Studio Edition Monitor application. A successful exploit of this vulnerability may lead to escalation of privileges, code execution, data tampering, denial of service, and information disclosure.
Source : NVD
## 7.3
Score
Published January 20, 2026
Severity HIGH
CNA Score 7.3
Affected Technologies
CUDA Toolkit
Linux Debian
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 5.2
Exploitation Probability (EPSS) N/A
Affected packages and libr
2026-01-20
Published