NVIDIA NeMo Framework
cpe:2.3:a:nvidia:nemo:*:*:*:*:*:*:*
- < 2.5.3
A code injection vulnerability has been identified in NVIDIA NeMo Framework, affecting all platforms and versions prior to 2.5.3. This vulnerability allows malicious data created by an attacker to be injected, potentially leading to arbitrary code execution, escalation of privileges, unauthorized information disclosure, and data tampering.
Exploitation of this vulnerability could result in arbitrary code execution, unauthorized privilege escalation, information disclosure, and data tampering.
Users are advised to update to version 2.5.3 or later. The updated version is available on the NVIDIA NeMo Framework GitHub releases page and on PyPI.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.