7.3
/ 10
HIGH
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
Description
NVIDIA NeMo framework contains a vulnerability in a predefined variable, where an attacker could cause inclusion of functionality from an untrusted control sphere by use of a predefined variable. A successful exploit of this vulnerability may lead to code execution.
Basic Information
ID
CVE-2025-33205
Source
nvidia
Published
Nov 25, 2025 at 18:07
Affected Product
Vendor
NVIDIA
Product
NeMo Framework
Version
All versions prior to 2.5.1
Affected Versions
NVIDIA NeMo Framework All versions prior to 2.5.1