NeMo Framework: Local command injection via unsanitized input passed to shell execution
Impact
A local user who controls the affected input can execute arbitrary OS commands in the context of the NeMo process. NVIDIA split this across 2 ids (CVE-2025-33246, -33249) in advisory 2026/5762, one per affected call site; both are CVSS 7.8 and both are closed by the same release.
Who can reach it
Malicious config / local user
What to do
Upgrade NeMo Framework to the fixed release from NVIDIA advisory 2026/5762 and rebuild training images; one bump closes both ids.
Also covers 1 CVE
The vendor assigned a separate id to each affected code path. They share this advisory, this score and this fix, so they are one entry here.
References
Related entries
- NeMo Framework: RCE via malicious YAML deserializationCVE-2026-24155 · NeMo FrameworkHigh
- NeMo Framework: unsafe deserialization of untrusted model data allows remote code executionCVE-2026-24157 · NeMo FrameworkHigh
- NeMo Framework: RCE via unsafe object deserializationCVE-2026-24228 · NeMo FrameworkHigh
- NeMo Framework: Command injection in script processingCVE-2026-24250 · NeMo FrameworkHigh
- NeMo Framework: RCE via insecure deserializationCVE-2025-23249 · NeMo FrameworkHigh
- NeMo Framework: Arbitrary file write/read via path traversalCVE-2025-23250 · NeMo FrameworkHigh
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.