NVIDIA NeMo Framework Code Injection Vulnerability in NLP and LLM Components

Vulnerability

A code injection vulnerability has been identified in the NVIDIA NeMo Framework, affecting all platforms and all versions prior to 2.5.1. The issue resides within the natural language processing (NLP) and large language model (LLM) components, where an attacker can inject malicious data that may be executed as code. This vulnerability could lead to unauthorized code execution, escalation of privileges, disclosure of sensitive information, and tampering with data.

Impact

Exploitation of this vulnerability allows for code execution, privilege escalation, unauthorized information disclosure, and data manipulation.

Remediation

Users are advised to update to version 2.5.1 or later. The updated version is available on the NVIDIA NeMo GitHub repository and through the Python Package Index (PyPI).

Added: Nov 25, 2025, 6:21 PM
Updated: Nov 25, 2025, 10:41 PM

Vulnerability Rating

Custom Algorithm
spread
2.4
impact
10.0
exploitability
4.7
remediation
7.7
relevance
1.1
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.