Model Loading Vulnerability in NVIDIA NeMo Framework
CVE-2025-33212

7.3HIGH

Key Information:

Vendor

Nvidia

Vendor
CVE Published:
16 December 2025

What is CVE-2025-33212?

The NVIDIA NeMo Framework contains a vulnerability related to model loading processes, which may allow an attacker to exploit inadequacies in control mechanisms. If a user inadvertently loads a maliciously crafted file, it could result in unauthorized code execution, privilege escalation, denial of service, and potential data manipulation. Users are urged to apply security best practices to mitigate the risks associated with this vulnerability.

Affected Version(s)

NeMo Framework All platforms All versions prior to 2.5.3

References

CVSS V3.1

Score:
7.3
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.