OS Command Injection Vulnerability in NVIDIA NeMo for Linux
CVE-2026-24252

7.8HIGH

Key Information:

Vendor

Nvidia

Vendor
CVE Published:
27 July 2026

What is CVE-2026-24252?

NVIDIA NeMo for Linux has a vulnerability that can be exploited to perform OS command injection, granting attackers the potential to execute arbitrary code. This could result in unauthorized data manipulation, privilege escalation, and sensitive information exposure, posing a significant risk to system integrity and security.

Affected Version(s)

NeMo Framework All platforms Versions 0.0 to 2.7.2

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.