CVE-2022-22821
Python vulnerability analysis and mitigation

Overview

NVIDIA NeMo before version 1.6.0 contains a vulnerability in ASR WebApp, where a Path Traversal attack using '../' structure may lead to deletion of any directory when admin privileges are available. The vulnerability was discovered on December 16, 2021, and was assigned CVE-2022-22821 (GitHub Advisory).

Technical details

The vulnerability is classified as CWE-23 (Relative Path Traversal) and affects the optional ASR WebApp tool. The issue stems from insufficient validation of user input in certain interfaces, allowing malicious actors to construct requests that can traverse directories using '../' patterns. The vulnerability only impacts scenarios where the web application is started with superuser permissions. This web app is not included in regular pip releases or containers, affecting only users who clone the entire repository and execute the web app with elevated privileges (GitHub Advisory).

Impact

The vulnerability has a relatively low severity with a CVSS score of 2.0 (AV:L/AC:L/PR:H/UI:R/S:U/C:N/I:L/A:N). When exploited, it could allow attackers to delete arbitrary directories on the system, though this requires both administrative privileges and user interaction (GitHub Advisory).

Exploitability

The vulnerability requires local access, high privileges (admin), and user interaction to be exploited. It specifically affects users who have cloned the repository and are running the ASR WebApp with superuser permissions (GitHub Advisory).

Mitigation and workarounds

The vulnerability has been patched in version 1.6.0 via commit f7e4ed7. Users can either upgrade to version 1.6.0 or later, or apply the changes from commit f7e4ed7 to their existing installation. Since the web app is not distributed via pip release or container, users who clone the main branch after this commit will automatically have the patch (GitHub Advisory).

Additional resources


SourceThis report was generated using AI

Related Python vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-55209CRITICAL9.8
  • Python logoPython
  • resdata
NoYesSep 14, 2026
CVE-2026-73496HIGH7.7
  • Python logoPython
  • mcp-atlassian
NoYesSep 14, 2026
CVE-2026-54559MEDIUM6.9
  • Python logoPython
  • pocketsphinx
NoYesSep 14, 2026
CVE-2026-73497MEDIUM6.5
  • Python logoPython
  • mcp-atlassian
NoYesSep 14, 2026
CVE-2026-55244MEDIUM5
  • Python logoPython
  • asteval
NoYesSep 14, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management