NVIDIA Isaac-GR00T N1.5: A second Python code-injection path in the same release
Impact
A second Python code-injection path in the same release. In an AI datacenter this is the model-and-data supply chain problem: the code runs with whatever the training or inference job holds, which is usually a GPU, a service account, and mounted object storage credentials.
Who can reach it
Requires the job to load an attacker-influenced artifact - a checkpoint, .nemo file, config, tokenizer or dataset. Any pipeline that pulls from a public model hub, a customer bucket, or a tenant-supplied path is in scope.
What to do
Bump the package to the fixed version in bulletin 5725 and rebuild every training/inference image that embeds it. Cost: image rebuild and job restart; no host driver or firmware change. The durable control is refusing to deserialize untrusted checkpoints at all - prefer safetensors-style formats and treat pickle-bearing artifacts as executable code.
References
Related entries
- NVIDIA Isaac-GR00T N1.5: A Python component injects code from crafted inputCVE-2025-33183 · NVIDIA Isaac-GR00T N1.5High
- NVIDIA DGX Spark (GB10) - SROOT / OSROOT root-of-trust firmware: An out-of-bounds write in SROOT firmware reaches codeCVE-2025-33189 · NVIDIA DGX Spark (GB10) - SROOT / OSROOT root-of-trust firmwareHigh
- NVIDIA NeMo Framework: Crafted data in the NLP and LLM components injects codeCVE-2025-33204 · NVIDIA NeMo FrameworkHigh
- Nsight Graphics: Local code exec via command injectionCVE-2025-33206 · Nsight GraphicsHigh
- GPU Display Driver: Local privesc to host root (use-after-free)CVE-2025-33217 · GPU Display DriverHigh
- GPU Display Driver: Kernel mode layer integer overflows allow local privilege escalationCVE-2025-33218 · GPU Display DriverHigh
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.