
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-33246 is a command injection vulnerability in the ASR (Automatic Speech Recognition) Evaluator utility of the NVIDIA NeMo Framework, affecting all platforms. A local user can trigger command injection by supplying crafted input to a configuration parameter, potentially leading to code execution, privilege escalation, data tampering, or information disclosure. The vulnerability affects all NeMo Framework versions prior to 2.6.1 and was published on February 18, 2026. It carries a CVSS v3.1 base score of 7.8 (High), assigned by NVIDIA Corporation (NVIDIA Advisory, Red Hat CVE).
The root cause is classified as CWE-77 (Improper Neutralization of Special Elements used in a Command — 'Command Injection'). The vulnerability resides in the ASR Evaluator utility of the NeMo Framework, where user-supplied input to a configuration parameter is not properly sanitized before being passed to a system command. Exploitation requires local access with low privileges (no user interaction needed), and the attack complexity is low, making it straightforward to exploit once local access is obtained (NVIDIA Advisory, Red Hat CVE).
Successful exploitation of CVE-2025-33246 can result in arbitrary code execution, escalation of privileges, data tampering, and information disclosure on the affected system. The vulnerability has high impact across all three security dimensions — confidentiality, integrity, and availability — meaning an attacker could fully compromise the host running the NeMo Framework. While the scope is unchanged (limited to the affected system), privilege escalation could enable further lateral movement within an environment (NVIDIA Advisory, Red Hat CVE).
As of the time of reporting, there is no public proof-of-concept exploit and no evidence of active in-the-wild exploitation (Red Hat CVE). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.046%, indicating a low current probability of exploitation in the near term. No threat actor attribution has been reported.
;, &&, |, or backticks) designed to inject additional OS commands./bin/sh, /bin/bash, cmd.exe) with unusual arguments or executing system utilities like curl, wget, nc, or python.;, &&, |, backticks, $()).NVIDIA has released a patch in NeMo Framework version 2.6.1, which resolves this vulnerability. All users running NeMo Framework versions prior to 2.6.1 on any platform should upgrade immediately. As interim mitigations, administrators should restrict local access to systems running NeMo Framework, enforce the principle of least privilege for user accounts, and validate or sanitize configuration parameters supplied to the ASR Evaluator utility (NVIDIA Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."