
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-33212 is a deserialization vulnerability in the NVIDIA NeMo Framework's model loading functionality that could allow an attacker to exploit improper control mechanisms when a user loads a maliciously crafted file. It affects all versions of NVIDIA NeMo Framework prior to 2.5.3. The vulnerability was disclosed on December 16, 2025, with NVD initial analysis completed on January 9, 2026. The NVD-assigned CVSS v3.1 base score is 7.8 (High), while NVIDIA's own CNA scoring is 7.3 (High) (NVIDIA Advisory, Red Hat CVE).
The root cause is classified as CWE-502 (Deserialization of Untrusted Data), mapped to CAPEC-586 (Object Injection). The vulnerability exists in the model loading component of the NeMo Framework, where improper control mechanisms fail to safely handle untrusted serialized data embedded in model files. An attacker must craft a malicious model file and convince a local user to load it — requiring local access and user interaction but no elevated privileges. No public technical write-up or proof-of-concept code has been identified at this time (NVIDIA Advisory, Red Hat CVE).
Successful exploitation can result in arbitrary code execution, escalation of privileges, denial of service, and data tampering on the affected system. All three security pillars — confidentiality, integrity, and availability — are rated as high impact. Because NeMo Framework is commonly used in AI/ML research and production environments, exploitation could expose sensitive model data, training datasets, or system credentials, and could serve as a foothold for lateral movement within a broader infrastructure (NVIDIA Advisory, Red Hat CVE).
There is no known public proof-of-concept exploit and no evidence of active in-the-wild exploitation at this time. The EPSS score is approximately 0.044%, indicating a low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires local access and user interaction (loading a malicious file), which limits the attack surface compared to remotely exploitable vulnerabilities (Red Hat CVE, NVIDIA Advisory).
.nemo, .ckpt, .pkl, or similar) in model directories; newly created scripts or binaries in user home or temp directories following a model load operation.curl, wget, or nc); unexpected process execution originating from NeMo model loading scripts.pickle, torch.load, or similar) in application logs; unexpected privilege escalation events in system authentication logs following NeMo usage.NVIDIA has released NeMo Framework version 2.5.3 to address this vulnerability; organizations should upgrade immediately (NVIDIA Advisory). As interim mitigations, restrict model file loading to trusted, verified sources only, and implement access controls to limit which users can load model files on NeMo-enabled systems. Educate users about the risks of loading model files from untrusted or unverified repositories, and monitor for suspicious model loading activity.
Security news outlet SecurityOnline.info covered the vulnerability as part of a broader NVIDIA AI patch advisory, noting risks of full code execution in both Isaac Lab and NeMo Framework (SecurityOnline). The vulnerability was noted on Mastodon's infosec community shortly after disclosure. Overall community reaction has been measured, reflecting the limited exploitability due to the local access and user interaction requirements.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."