NVIDIA runx: Arbitrary command exec via shell metacharacter injection
CVSS 7.8CVE-2025-33234NVIDIA / GPU stackcurated
Impact
Arbitrary command exec via shell metacharacter injection
Who can reach it
Local user invoking the tool
What to do
Upgrade runx on nodes
References
Related entries
- NVIDIA Resiliency Extension: A race condition in the checkpointing core reaches information disclosure, data tamperingCVE-2025-33235 · NVIDIA Resiliency ExtensionHigh
- NeMo Framework: Arbitrary Python code exec via code injectionCVE-2025-33236 · NeMo FrameworkHigh
- Megatron-Bridge: code injection via malicious input in the data merging and data shuffling tutorialsCVE-2025-33239 · Megatron-BridgeHigh
- NeMo Framework: Unsafe deserialization of untrusted model/config data allows arbitrary code executionCVE-2025-33241 · NeMo FrameworkHigh
- NeMo Framework: Local command injection via unsanitized input passed to shell executionCVE-2025-33246 · NeMo FrameworkHigh
- Megatron-LM: Local privesc / RCE via unsafe pickle deserializationCVE-2025-33247 · Megatron-LMHigh
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.