NVIDIA NeMo Framework
cpe:2.3:a:nvidia:nemo:*:*:*:*:*:*:*
- < 2.5.1
A code injection vulnerability has been identified in the NVIDIA NeMo Framework, affecting all platforms and all versions prior to 2.5.1. The issue resides within the natural language processing (NLP) and large language model (LLM) components, where an attacker can inject malicious data that may be executed as code. This vulnerability could lead to unauthorized code execution, escalation of privileges, disclosure of sensitive information, and tampering with data.
Exploitation of this vulnerability allows for code execution, privilege escalation, unauthorized information disclosure, and data manipulation.
Users are advised to update to version 2.5.1 or later. The updated version is available on the NVIDIA NeMo GitHub repository and through the Python Package Index (PyPI).
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.