CVE-2026-24252
published 2026-07-27CVE-2026-24252: NVIDIA NeMo for Linux contains a vulnerability where an attacker may cause OS command injection. A successful exploit of this vulnerability may lead to code…
PriorityP346high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.88%
57.6th percentile
NVIDIA NeMo for Linux contains a vulnerability where an attacker may cause OS command injection. A successful exploit of this vulnerability may lead to code execution, data tampering, escalation of privileges and information disclosure.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| nvidia | nemo | < 2.7.3 | 2.7.3 |
| nvidia | nemo_framework | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
NVIDIA NeMo Framework os command injection
vuldb·2026-09-05·CVSS 7.8
CVE-2026-24252 [HIGH] NVIDIA NeMo Framework os command injection
A vulnerability was found in NVIDIA NeMo Framework. It has been declared as very critical. This issue affects some unknown processing. The manipulation results in os command injection.
This vulnerability was named CVE-2026-24252. The attack may be performed from remote. There is no available exploit.
GHSA
NVIDIA NeMo for Linux contains a vulnerability where an attacker may cause OS command injection.
ghsa_unreviewed·2026-07-27
CVE-2026-24252 [HIGH] CWE-78 NVIDIA NeMo for Linux contains a vulnerability where an attacker may cause OS command injection.
NVIDIA NeMo for Linux contains a vulnerability where an attacker may cause OS command injection. A successful exploit of this vulnerability may lead to code execution, data tampering, escalation of privileges and information disclosure.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-07-27
Published