{"id":"CVE-2026-24252","title":"NVIDIA NeMo for Linux contains a vulnerability where an attacker may cause OS command injection","summary":"NVIDIA NeMo for Linux contains a vulnerability where an attacker may cause OS command injection. A successful exploit of this vulnerability may lead to code execution, data tampering, escalation of privileges and information disclosure.","severity":"high","cvss":7.8,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","cwe":["CWE-78"],"vendor":"nvidia","product":"nemo","affected":["nemo < 2.7.3"],"patched":["nemo 2.7.3"],"published":"2026-07-27","updated":"2026-09-04","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-24252","references":[{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-24252","label":"psirt@nvidia.com"},{"url":"https://nvidia.custhelp.com/app/answers/detail/a_id/5839","label":"psirt@nvidia.com"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-24252","label":"psirt@nvidia.com"}],"tags":["nvd"],"epss":0.00878,"epssPercentile":0.57527,"ingestedAt":"2026-09-05T15:41:15.991Z","slug":"CVE-2026-24252","body":"## Overview\n\nNVIDIA NeMo for Linux contains a vulnerability where an attacker may cause OS command injection. A successful exploit of this vulnerability may lead to code execution, data tampering, escalation of privileges and information disclosure.\n\n## Affected\n\n- `nemo < 2.7.3`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `nemo 2.7.3`","depth":"twilight","depthScore":43,"depthScoreParts":{"impact":42.9,"likelihood":0.2,"exploitation":0,"ransomware":0},"changes":[]}