NVIDIA NeMo Framework Model Loading Vulnerability Allowing Code Execution and Privilege Escalation

Vulnerability

A vulnerability has been identified in the NVIDIA NeMo Framework related to model loading. This issue could enable an attacker to exploit improper control mechanisms by having a user load a maliciously crafted file. Exploitation of this vulnerability could result in code execution, unauthorized privilege escalation, denial of service, and data tampering.

Impact

Exploitation of this vulnerability could lead to code execution, escalation of privileges, denial of service, and unauthorized data modification.

Remediation

Users are advised to update to version 2.5.3 or later. The updated version is available on the NVIDIA NeMo Framework GitHub releases page and through the Python Package Index (PyPI).

Added: Dec 16, 2025, 7:19 PM
Updated: Dec 16, 2025, 7:19 PM

Vulnerability Rating

Custom Algorithm
spread
2.4
impact
10.0
exploitability
4.4
remediation
7.7
relevance
1.5
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.