NVIDIA NeMo Framework
cpe:2.3:a:nvidia:nemo:*:*:*:*:*:*:*
- < 2.5.0
A code injection vulnerability has been identified in the NVIDIA NeMo Framework, affecting all platforms and versions prior to 2.5.0. This vulnerability allows attackers to manipulate code generation processes, potentially leading to unauthorized code execution, elevated privileges, information disclosure, and data tampering.
Exploitation of this vulnerability could result in unauthorized code execution, escalation of privileges, unauthorized information disclosure, and unauthorized data modification.
Users are advised to update to version 2.5.0 or later. The updated version is available on the NVIDIA GitHub releases page and through the Python Package Index (PyPI).
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.