
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-33245 is a deserialization of untrusted data vulnerability (CWE-502) in the NVIDIA NeMo Framework that can allow a network-adjacent authenticated attacker to trigger remote code execution via malicious data. It affects all NeMo Framework versions prior to 2.6.1. The vulnerability was published on February 18, 2026, with NIST's initial analysis completed on February 20, 2026. The CVSS v3.1 base score is 8.8 (High) per NVD, and 8.0 (High) per NVIDIA's own CNA assessment (NVD, NVIDIA Advisory).
The root cause is improper deserialization of untrusted data (CWE-502), classified under CAPEC-586 (Object Injection). An attacker with low privileges can supply crafted malicious data to the NeMo Framework over the network, which is deserialized without adequate validation, leading to arbitrary code execution. The NVIDIA CNA vector indicates user interaction is required (UI:R), while NVD's enrichment scores it without user interaction (UI:N), suggesting some ambiguity in the exact attack path. No public proof-of-concept code has been observed as of the time of disclosure (NVD, NVIDIA Advisory).
Successful exploitation of CVE-2025-33245 can result in full compromise of the affected NeMo Framework instance, including arbitrary remote code execution, privilege escalation, unauthorized information disclosure, and data tampering. Given that NeMo is an AI/ML framework often used in research and production AI pipelines, exploitation could expose sensitive model data, training datasets, or proprietary configurations. The high scores across confidentiality, integrity, and availability impact underscore the severity of a successful attack (NVD, NVIDIA Advisory).
As of the disclosure date, there is no public proof-of-concept exploit and no confirmed in-the-wild exploitation of CVE-2025-33245. The EPSS score is approximately 0.343%, indicating a low probability of exploitation in the near term. The vulnerability requires only low privileges and no user interaction (per NVD scoring), making it relatively accessible to network-based attackers if exposed. It has not been added to the CISA Known Exploited Vulnerabilities (KEV) catalog. The vulnerability is detectable by Qualys scanners (detection ID 5007920) (NVD, Feedly).
NVIDIA has released a patch addressing this vulnerability in NeMo Framework version 2.6.1. Users should upgrade to version 2.6.1 or later immediately. No specific configuration-based workarounds have been published; upgrading is the recommended and only confirmed remediation. Organizations using NeMo in production AI pipelines should treat this as a high-priority update given the remote exploitability and high impact scores (NVIDIA Advisory, NVD).
Heise (a German technology publication) covered the vulnerability in the context of NVIDIA AI tools — including NeMo Framework and Megatron Bridge — being potential entry points for attackers, highlighting broader concerns about AI framework security (Heise). Red Hat also tracked the vulnerability via their security advisory system. No significant researcher commentary or social media debate has been observed beyond standard vulnerability aggregator coverage.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."