Deserialization of Untrusted Data in NVIDIA Nemo Framework - CVE-2025-33212
Published: May 18, 2026
NVIDIA Nemo Framework
Detailed vulnerability description
The vulnerability allows a local user to execute arbitrary code, escalate privileges, cause a denial of service, or tamper with data.
The vulnerability exists due to deserialization of untrusted data in model loading when loading a maliciously crafted file. A local user can supply a maliciously crafted file to execute arbitrary code, escalate privileges, cause a denial of service, or tamper with data.
User interaction is required to load a crafted file.