{"id":"CVE-2025-33245","aliases":["GHSA-9379-mwvr-7wxx","PYSEC-2026-2672"],"title":"NVIDIA NeMo Framework contains a vulnerability where malicious data could cause remote code execution","summary":"NVIDIA NeMo Framework contains a vulnerability where malicious data could cause remote code execution","severity":"high","cvss":8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H","vendor":"nemo-toolkit","product":"nemo-toolkit","ecosystem":"pip","affected":["nemo-toolkit < 2.6.1"],"patched":["nemo-toolkit 2.6.1"],"published":"2026-02-18","updated":"2026-07-13","source":"OSV","sourceUrl":"https://osv.dev/vulnerability/GHSA-9379-mwvr-7wxx","references":[{"url":"https://nvd.nist.gov/vuln/detail/CVE-2025-33245"},{"url":"https://github.com/NVIDIA-NeMo/NeMo"},{"url":"https://nvidia.custhelp.com/app/answers/detail/a_id/5762"},{"url":"https://www.cve.org/CVERecord?id=CVE-2025-33245"}],"tags":["osv","pip"],"epss":0.0054,"epssPercentile":0.44325,"ingestedAt":"2026-07-13T18:57:55.654Z","slug":"CVE-2025-33245","body":"## Overview\n\nNVIDIA NeMo Framework contains a vulnerability where malicious data could cause remote code execution. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, information disclosure, and data tampering.\n\n## Affected packages\n\n- `nemo-toolkit < 2.6.1`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `nemo-toolkit 2.6.1`","depth":"twilight","depthScore":44,"depthScoreParts":{"impact":44,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}