CVE-2022-22821
Python vulnerability analysis and mitigation

Overview

NVIDIA NeMo before version 1.6.0 contains a vulnerability in ASR WebApp, where a Path Traversal attack using '../' structure may lead to deletion of any directory when admin privileges are available. The vulnerability was discovered on December 16, 2021, and was assigned CVE-2022-22821 (GitHub Advisory).

Technical details

The vulnerability is classified as CWE-23 (Relative Path Traversal) and affects the optional ASR WebApp tool. The issue stems from insufficient validation of user input in certain interfaces, allowing malicious actors to construct requests that can traverse directories using '../' patterns. The vulnerability only impacts scenarios where the web application is started with superuser permissions. This web app is not included in regular pip releases or containers, affecting only users who clone the entire repository and execute the web app with elevated privileges (GitHub Advisory).

Impact

The vulnerability has a relatively low severity with a CVSS score of 2.0 (AV:L/AC:L/PR:H/UI:R/S:U/C:N/I:L/A:N). When exploited, it could allow attackers to delete arbitrary directories on the system, though this requires both administrative privileges and user interaction (GitHub Advisory).

Mitigation and workarounds

The vulnerability has been patched in version 1.6.0 via commit f7e4ed7. Users can either upgrade to version 1.6.0 or later, or apply the changes from commit f7e4ed7 to their existing installation. Since the web app is not distributed via pip release or container, users who clone the main branch after this commit will automatically have the patch (GitHub Advisory).

Additional resources


SourceThis report was generated using AI

Related Python vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

GHSA-5882-5rx9-xgxpCRITICAL10
  • PythonPython
  • crawl4ai
NoYesJan 16, 2026
CVE-2026-23949HIGH8.6
  • PythonPython
  • jaraco.context
NoYesJan 20, 2026
GHSA-vx9w-5cx4-9796HIGH8.6
  • PythonPython
  • crawl4ai
NoYesJan 16, 2026
CVE-2026-23535HIGH8
  • PythonPython
  • wlc
NoYesJan 16, 2026
CVE-2026-23490HIGH7.5
  • PythonPython
  • fence-agents-intelmodular
NoYesJan 16, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management