Nvidia Nemo Framework vulnerabilities

26 known vulnerabilities affecting nvidia/nemo_framework.

Total CVEs
26
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL6HIGH20

Vulnerabilities

Page 1 of 2
CVE-2026-24159CRITICALCVSS 9.8vAll versions prior to 2.6.22026-03-24
CVE-2026-24159 [HIGH] CWE-502 CVE-2026-24159: NVIDIA NeMo Framework contains a vulnerability where an attacker may cause remote code execution. A NVIDIA NeMo Framework contains a vulnerability where an attacker may cause remote code execution. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, information disclosure and data tampering.
cvelistv5nvd
CVE-2026-24157CRITICALCVSS 9.8vAll versions prior to 2.6.22026-03-24
CVE-2026-24157 [HIGH] CWE-502 CVE-2026-24157: NVIDIA NeMo Framework contains a vulnerability in checkpoint loading where an attacker could cause r NVIDIA NeMo Framework contains a vulnerability in checkpoint loading where an attacker could cause remote code execution. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, information disclosure and data tampering.
cvelistv5nvd
CVE-2025-33245HIGHCVSS 8.8vAll versions prior to 2.6.12026-02-18
CVE-2025-33245 [HIGH] CWE-502 CVE-2025-33245: NVIDIA NeMo Framework contains a vulnerability where malicious data could cause remote code executio NVIDIA NeMo Framework contains a vulnerability where malicious data could cause remote code execution. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, information disclosure, and data tampering.
cvelistv5nvd
CVE-2025-33250HIGHCVSS 7.8vAll versions prior to 2.6.12026-02-18
CVE-2025-33250 [HIGH] CWE-94 CVE-2025-33250: NVIDIA NeMo Framework contains a vulnerability where an attacker could cause remote code execution. NVIDIA NeMo Framework contains a vulnerability where an attacker could cause remote code execution. A successful exploit of this vulnerability might lead to code execution, denial of service, information disclosure, and data tampering.
cvelistv5nvd
CVE-2025-33251HIGHCVSS 7.8vAll versions prior to 2.6.12026-02-18
CVE-2025-33251 [HIGH] CWE-94 CVE-2025-33251: NVIDIA NeMo Framework contains a vulnerability where an attacker could cause remote code execution. NVIDIA NeMo Framework contains a vulnerability where an attacker could cause remote code execution. A successful exploit of this vulnerability might lead to code execution, denial of service, information disclosure, and data tampering.
cvelistv5nvd
CVE-2025-33249HIGHCVSS 7.8vAll versions prior to 2.6.12026-02-18
CVE-2025-33249 [HIGH] CWE-77 CVE-2025-33249: NVIDIA NeMo Framework for all platforms contains a vulnerability in a voice-preprocessing script, wh NVIDIA NeMo Framework for all platforms contains a vulnerability in a voice-preprocessing script, where malicious input created by an attacker could cause a code injection. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, information disclosure, and data tampering.
cvelistv5nvd
CVE-2025-33241HIGHCVSS 7.8vAll versions prior to 2.6.12026-02-18
CVE-2025-33241 [HIGH] CWE-502 CVE-2025-33241: NVIDIA NeMo Framework contains a vulnerability where an attacker could cause remote code execution b NVIDIA NeMo Framework contains a vulnerability where an attacker could cause remote code execution by loading a maliciously crafted file. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, information disclosure, and data tampering.
cvelistv5nvd
CVE-2025-33243HIGHCVSS 7.8vAll versions prior to 2.6.12026-02-18
CVE-2025-33243 [HIGH] CWE-502 CVE-2025-33243: NVIDIA NeMo Framework contains a vulnerability where an attacker could cause remote code execution i NVIDIA NeMo Framework contains a vulnerability where an attacker could cause remote code execution in distributed environments. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, information disclosure, and data tampering.
cvelistv5nvd
CVE-2025-33252HIGHCVSS 7.8vAll versions prior to 2.6.12026-02-18
CVE-2025-33252 [HIGH] CWE-502 CVE-2025-33252: NVIDIA NeMo Framework contains a vulnerability where an attacker could cause remote code execution. NVIDIA NeMo Framework contains a vulnerability where an attacker could cause remote code execution. A successful exploit of this vulnerability might lead to code execution, denial of service, information disclosure, and data tampering.
cvelistv5nvd
CVE-2025-33236HIGHCVSS 7.8vAll versions prior to 2.6.12026-02-18
CVE-2025-33236 [HIGH] CWE-94 CVE-2025-33236: NVIDIA NeMo Framework contains a vulnerability where malicious data created by an attacker could cau NVIDIA NeMo Framework contains a vulnerability where malicious data created by an attacker could cause code injection. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, information disclosure, and data tampering.
cvelistv5nvd
CVE-2025-33253HIGHCVSS 7.3vAll versions prior to 2.6.12026-02-18
CVE-2025-33253 [HIGH] CWE-502 CVE-2025-33253: NVIDIA NeMo Framework contains a vulnerability where an attacker could cause remote code execution b NVIDIA NeMo Framework contains a vulnerability where an attacker could cause remote code execution by convincing a user to load a maliciously crafted file. A successful exploit of this vulnerability might lead to code execution, denial of service, information disclosure, and data tampering.
cvelistv5nvd
CVE-2025-33246HIGHCVSS 7.8vAll versions prior to 2.6.12026-02-18
CVE-2025-33246 [HIGH] CWE-77 CVE-2025-33246: NVIDIA NeMo Framework for all platforms contains a vulnerability in the ASR Evaluator utility, where NVIDIA NeMo Framework for all platforms contains a vulnerability in the ASR Evaluator utility, where a user could cause a command injection by supplying crafted input to a configuration parameter. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, or information disclosure.
cvelistv5nvd
CVE-2025-33226HIGHCVSS 7.8vAll versions prior to 2.5.32025-12-16
CVE-2025-33226 [HIGH] CWE-502 CVE-2025-33226: NVIDIA NeMo Framework for all platforms contains a vulnerability where malicious data created by an NVIDIA NeMo Framework for all platforms contains a vulnerability where malicious data created by an attacker may cause a code injection. A successful exploit of this vulnerability may lead to code execution, escalation of privileges, information disclosure, and data tampering.
cvelistv5nvd
CVE-2025-33212HIGHCVSS 7.8vAll versions prior to 2.5.32025-12-16
CVE-2025-33212 [HIGH] CWE-502 CVE-2025-33212: NVIDIA NeMo Framework contains a vulnerability in model loading that could allow an attacker to expl NVIDIA NeMo Framework contains a vulnerability in model loading that could allow an attacker to exploit improper control mechanisms if a user loads a maliciously crafted file. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, denial of service, and data tampering.
cvelistv5nvd
CVE-2025-33205HIGHCVSS 7.3vAll versions prior to 2.5.12025-11-25
CVE-2025-33205 [HIGH] CWE-829 CVE-2025-33205: NVIDIA NeMo framework contains a vulnerability in a predefined variable, where an attacker could cau NVIDIA NeMo framework contains a vulnerability in a predefined variable, where an attacker could cause inclusion of functionality from an untrusted control sphere by use of a predefined variable. A successful exploit of this vulnerability may lead to code execution.
cvelistv5nvd
CVE-2025-33204HIGHCVSS 7.8vAll versions prior to 2.5.12025-11-25
CVE-2025-33204 [HIGH] CWE-94 CVE-2025-33204: NVIDIA NeMo Framework for all platforms contains a vulnerability in the NLP and LLM components, wher NVIDIA NeMo Framework for all platforms contains a vulnerability in the NLP and LLM components, where malicious data created by an attacker could cause code injection. A successful exploit of this vulnerability may lead to code execution, escalation of privileges, information disclosure, and data tampering.
cvelistv5nvd
CVE-2025-33178HIGHCVSS 7.8vAll versions prior to 2.5.02025-11-11
CVE-2025-33178 [HIGH] CWE-94 CVE-2025-33178: NVIDIA NeMo Framework for all platforms contains a vulnerability in the bert services component wher NVIDIA NeMo Framework for all platforms contains a vulnerability in the bert services component where malicious data created by an attacker may cause a code injection. A successful exploit of this vulnerability may lead to Code execution, Escalation of privileges, Information disclosure, and Data tampering.
cvelistv5nvd
CVE-2025-23361HIGHCVSS 7.8vAll versions prior to 2.5.02025-11-11
CVE-2025-23361 [HIGH] CWE-94 CVE-2025-23361: NVIDIA NeMo Framework for all platforms contains a vulnerability in a script, where malicious input NVIDIA NeMo Framework for all platforms contains a vulnerability in a script, where malicious input created by an attacker may cause improper control of code generation. A successful exploit of this vulnerability may lead to code execution, escalation of privileges, information disclosure, and data tampering.
cvelistv5nvd
CVE-2025-23312HIGHCVSS 7.8vAll versions prior to 2.4.02025-08-26
CVE-2025-23312 [HIGH] CWE-94 CVE-2025-23312: NVIDIA NeMo Framework for all platforms contains a vulnerability in the retrieval services component NVIDIA NeMo Framework for all platforms contains a vulnerability in the retrieval services component, where malicious data created by an attacker could cause a code injection. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, information disclosure, and data tampering.
cvelistv5nvd
CVE-2025-23313HIGHCVSS 7.8vAll versions prior to 2.4.02025-08-26
CVE-2025-23313 [HIGH] CWE-94 CVE-2025-23313: NVIDIA NeMo Framework for all platforms contains a vulnerability in the NLP component, where malicio NVIDIA NeMo Framework for all platforms contains a vulnerability in the NLP component, where malicious data created by an attacker could cause a code injection issue. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, information disclosure, and data tampering.
cvelistv5nvd
Nvidia Nemo Framework vulnerabilities | cvebase