CVE-2025-33245
Python vulnerability analysis and mitigation

Overview

CVE-2025-33245 is a deserialization of untrusted data vulnerability (CWE-502) in the NVIDIA NeMo Framework that can allow a network-adjacent authenticated attacker to trigger remote code execution via malicious data. It affects all NeMo Framework versions prior to 2.6.1. The vulnerability was published on February 18, 2026, with NIST's initial analysis completed on February 20, 2026. The CVSS v3.1 base score is 8.8 (High) per NVD, and 8.0 (High) per NVIDIA's own CNA assessment (NVD, NVIDIA Advisory).

Technical details

The root cause is improper deserialization of untrusted data (CWE-502), classified under CAPEC-586 (Object Injection). An attacker with low privileges can supply crafted malicious data to the NeMo Framework over the network, which is deserialized without adequate validation, leading to arbitrary code execution. The NVIDIA CNA vector indicates user interaction is required (UI:R), while NVD's enrichment scores it without user interaction (UI:N), suggesting some ambiguity in the exact attack path. No public proof-of-concept code has been observed as of the time of disclosure (NVD, NVIDIA Advisory).

Impact

Successful exploitation of CVE-2025-33245 can result in full compromise of the affected NeMo Framework instance, including arbitrary remote code execution, privilege escalation, unauthorized information disclosure, and data tampering. Given that NeMo is an AI/ML framework often used in research and production AI pipelines, exploitation could expose sensitive model data, training datasets, or proprietary configurations. The high scores across confidentiality, integrity, and availability impact underscore the severity of a successful attack (NVD, NVIDIA Advisory).

Exploitability

As of the disclosure date, there is no public proof-of-concept exploit and no confirmed in-the-wild exploitation of CVE-2025-33245. The EPSS score is approximately 0.343%, indicating a low probability of exploitation in the near term. The vulnerability requires only low privileges and no user interaction (per NVD scoring), making it relatively accessible to network-based attackers if exposed. It has not been added to the CISA Known Exploited Vulnerabilities (KEV) catalog. The vulnerability is detectable by Qualys scanners (detection ID 5007920) (NVD, Feedly).

Mitigation and workarounds

NVIDIA has released a patch addressing this vulnerability in NeMo Framework version 2.6.1. Users should upgrade to version 2.6.1 or later immediately. No specific configuration-based workarounds have been published; upgrading is the recommended and only confirmed remediation. Organizations using NeMo in production AI pipelines should treat this as a high-priority update given the remote exploitability and high impact scores (NVIDIA Advisory, NVD).

Community reactions

Heise (a German technology publication) covered the vulnerability in the context of NVIDIA AI tools — including NeMo Framework and Megatron Bridge — being potential entry points for attackers, highlighting broader concerns about AI framework security (Heise). Red Hat also tracked the vulnerability via their security advisory system. No significant researcher commentary or social media debate has been observed beyond standard vulnerability aggregator coverage.

Additional resources


SourceThis report was generated using AI

Related Python vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-50027CRITICAL9.8
  • Python logoPython
  • mcp-memory-service
NoYesAug 14, 2026
CVE-2026-49986HIGH7.1
  • Python logoPython
  • neuro-cortex-memory
NoYesAug 14, 2026
CVE-2026-53708MEDIUM6.6
  • Python logoPython
  • mcp-contextforge-gateway
NoYesAug 14, 2026
CVE-2026-47192LOW2.1
  • Python logoPython
  • kas
NoYesAug 14, 2026
CVE-2026-47191LOW2.1
  • Python logoPython
  • kas
NoYesAug 14, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management