Code Injection in NVIDIA Nemo Framework - CVE-2025-23361
Published: May 19, 2026
NVIDIA Nemo Framework
Detailed vulnerability description
The vulnerability allows a local user to execute arbitrary code, escalate privileges, disclose sensitive information, and tamper with data.
The vulnerability exists due to improper control of code generation in a script when processing malicious input. A local user can provide malicious input to execute arbitrary code, escalate privileges, disclose sensitive information, and tamper with data.