{"id":"CVE-2025-33253","aliases":["GHSA-hvjw-vp7g-39h5","PYSEC-2026-2673"],"title":"NVIDIA NeMo Framework Deserializes Untrusted Data","summary":"NVIDIA NeMo Framework Deserializes Untrusted Data","severity":"high","cvss":7.8,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","vendor":"nemo-toolkit","product":"nemo-toolkit","ecosystem":"pip","affected":["nemo-toolkit < 2.6.1"],"patched":["nemo-toolkit 2.6.1"],"published":"2026-02-18","updated":"2026-07-13","source":"OSV","sourceUrl":"https://osv.dev/vulnerability/GHSA-hvjw-vp7g-39h5","references":[{"url":"https://nvd.nist.gov/vuln/detail/CVE-2025-33253"},{"url":"https://github.com/NVIDIA-NeMo/NeMo"},{"url":"https://nvidia.custhelp.com/app/answers/detail/a_id/5762"},{"url":"https://www.cve.org/CVERecord?id=CVE-2025-33253"}],"tags":["osv","pip"],"epss":0.00193,"epssPercentile":0.09299,"ingestedAt":"2026-07-13T18:57:59.473Z","slug":"CVE-2025-33253","body":"## Overview\n\nNVIDIA NeMo Framework contains a vulnerability where an attacker could cause remote code execution by convincing a user to load a maliciously crafted file. A successful exploit of this vulnerability might lead to code execution, denial of service, information disclosure, and data tampering.\n\n## Affected packages\n\n- `nemo-toolkit < 2.6.1`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `nemo-toolkit 2.6.1`","depth":"twilight","depthScore":43,"depthScoreParts":{"impact":42.9,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}