Predefined Variable Vulnerability in NVIDIA NeMo Framework
CVE-2025-33205

7.3HIGH

Key Information:

Vendor

Nvidia

Vendor
CVE Published:
25 November 2025

What is CVE-2025-33205?

The NVIDIA NeMo framework has a vulnerability that arises from a predefined variable that can be exploited by an attacker. This flaw enables the inclusion of unauthorized functionality from an untrusted control sphere, potentially allowing for the execution of arbitrary code. Organizations utilizing this framework should be cautious and review their security protocols to mitigate the risk associated with this vulnerability.

Affected Version(s)

NeMo Framework All platforms All versions prior to 2.5.1

References

CVSS V3.1

Score:
7.3
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.