{"id":"CVE-2026-24159","aliases":["GHSA-v7v2-m736-cf3c","PYSEC-2026-2675"],"title":"NVIDIA NeMo Framework contains a vulnerability leading to Remote Code Execution","summary":"NVIDIA NeMo Framework contains a vulnerability leading to Remote Code Execution","severity":"high","cvss":7.8,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","vendor":"nemo-toolkit","product":"nemo-toolkit","ecosystem":"pip","affected":["nemo-toolkit < 2.6.2"],"patched":["nemo-toolkit 2.6.2"],"published":"2026-03-24","updated":"2026-07-13","source":"OSV","sourceUrl":"https://osv.dev/vulnerability/GHSA-v7v2-m736-cf3c","references":[{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-24159"},{"url":"https://github.com/NVIDIA-NeMo/NeMo"},{"url":"https://nvidia.custhelp.com/app/answers/detail/a_id/5800"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-24159"}],"tags":["osv","pip"],"epss":0.00641,"epssPercentile":0.49303,"ingestedAt":"2026-07-13T18:58:03.335Z","slug":"CVE-2026-24159","body":"## Overview\n\nNVIDIA NeMo Framework contains a vulnerability where an attacker may cause remote code execution. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, information disclosure and data tampering.\n\n## Affected packages\n\n- `nemo-toolkit < 2.6.2`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `nemo-toolkit 2.6.2`","depth":"twilight","depthScore":43,"depthScoreParts":{"impact":42.9,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}