
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-33226 is a code injection vulnerability in the NVIDIA NeMo Framework affecting all platforms. It stems from unsafe deserialization of untrusted data (CWE-502), where malicious data crafted by an attacker can trigger code injection. All versions of NeMo Framework prior to 2.5.3 are affected. The vulnerability was disclosed on December 16, 2025, with a CVSS v3.1 base score of 7.8 (High), assigned by NVIDIA Corporation (NVIDIA Advisory, Red Hat CVE).
The root cause is classified as CWE-502 (Deserialization of Untrusted Data), mapped to CAPEC-586 (Object Injection). An attacker with low-privilege local access can supply maliciously crafted data to the NeMo Framework, which is deserialized without adequate validation, resulting in arbitrary code injection. The attack vector is local (AV:L), requires low privileges (PR:L), has low complexity (AC:L), and requires no user interaction, making it straightforward to exploit in environments where untrusted data is processed (NVIDIA Advisory, Red Hat CVE).
Successful exploitation can lead to arbitrary code execution, escalation of privileges, information disclosure, and data tampering on the affected system. The vulnerability poses a significant risk in multi-user or shared AI/ML infrastructure environments where NeMo Framework processes data from multiple sources, as a low-privileged attacker could escalate to higher access levels and compromise confidentiality, integrity, and availability of the system (NVIDIA Advisory, Red Hat CVE).
As of the time of reporting, there is no public proof-of-concept exploit and no evidence of in-the-wild exploitation (Red Hat CVE). The EPSS score is approximately 0.062%, indicating a currently low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported.
NVIDIA has released a patch in NeMo Framework version 2.5.3; users should upgrade immediately across all deployments (NVIDIA Advisory). As interim mitigations, restrict local access to systems running NeMo Framework to trusted users only, apply the principle of least privilege for process execution, and avoid processing untrusted or externally sourced data files with the framework. Monitor for suspicious privilege escalation attempts and unauthorized data processing activities.
Security news outlet SecurityOnline.info covered the vulnerability as part of a broader NVIDIA AI patch advisory, noting risks of full code execution in Isaac Lab and NeMo Framework (SecurityOnline). Rewterz published a threat advisory covering multiple NVIDIA product vulnerabilities including CVE-2025-33226 (Rewterz). Community discussion on Mastodon (infosec.exchange) noted the disclosure shortly after publication, with no significant controversy or widespread alarm observed.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."