NVIDIA NeMo Curator Code Injection Vulnerability Allowing Remote Code Execution and Privilege Escalation
Vulnerability
A code injection vulnerability has been identified in NVIDIA NeMo Curator, affecting all platforms and versions prior to Curator 25.07. This vulnerability allows an attacker to create a malicious file that could be used to inject code. Exploitation of this issue could lead to unauthorized code execution, escalation of privileges, information disclosure, and data tampering.
Impact
Exploitation of this vulnerability could result in unauthorized code execution, elevated privileges, disclosure of sensitive information, and unauthorized modification of data.
Remediation
Users are advised to upgrade to the latest version of NVIDIA NeMo Curator, available on the NVIDIA GitHub page. For more information, visit the NVIDIA Product Security page.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
