NVIDIA Nemo
Don't miss out!
Thousands of developers use stack.watch to stay informed.Get an email whenever new security vulnerabilities are reported in NVIDIA Nemo.
Recent NVIDIA Nemo Security Advisories
| Advisory | Title | Published |
|---|---|---|
| 5872 | Security Bulletin: NVIDIA NemoClaw and OpenShell - August 2026 | August 25, 2026 |
| 5839 | Security Bulletin: NVIDIA NeMo - June 2026 | June 16, 2026 |
| 5831 | Security Bulletin: NVIDIA BioNeMo Framework - May 2026 | May 19, 2026 |
| 5837 | Security Bulletin: NVIDIA NemoClaw - April 2026 | April 28, 2026 |
| 5808 | Security Bulletin: NVIDIA BioNeMo Framework - March 2026 | March 31, 2026 |
| 5800 | Security Bulletin: NVIDIA NeMo Framework - March 2026 | March 24, 2026 |
| 5762 | Security Bulletin: NVIDIA NeMo Framework - February 2026 | February 17, 2026 |
| 5736 | Security Bulletin: NVIDIA NeMo Framework - December 2025 | December 16, 2025 |
| 5729 | Security Bulletin: NVIDIA NeMo Framework - November 2025 | November 25, 2025 |
| 5726 | Security Bulletin: NVIDIA NeMo Agent Toolkit - November 2025 | November 25, 2025 |
By the Year
In 2026 there have been 33 vulnerabilities in NVIDIA Nemo with an average score of 7.7 out of ten. Last year, in 2025 Nemo had 10 security vulnerabilities published. That is, 23 more vulnerabilities have already been reported in 2026 as compared to last year. However, the average CVE base score of the vulnerabilities in 2026 is greater by 0.09.
| Year | Vulnerabilities | Average Score |
|---|---|---|
| 2026 | 33 | 7.71 |
| 2025 | 10 | 7.62 |
| 2024 | 1 | 7.80 |
| 2023 | 0 | 0.00 |
| 2022 | 1 | 4.40 |
It may take a day or so for new Nemo vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.
Recent NVIDIA Nemo Security Vulnerabilities
NVIDIA NemoClaw: Inference Service Bypass (auth) Info Leak & DoS
CVE-2026-65105
8.1 - High
- August 25, 2026
NVIDIA NemoClaw for Linux contains a vulnerability in its inference server setup, where a remote attacker may access the inference service without authentication. A successful exploit of this vulnerability may lead to information disclosure and denial of service.
Missing Authentication for Critical Function
NVIDIA NemoClaw Info Disclosure via Sensitive Data Process Invocation
CVE-2026-65088
5.5 - Medium
- August 25, 2026
NVIDIA NemoClaw contains a vulnerability where an attacker could cause invocation of process using visible sensitive information. A successful exploit of this vulnerability might lead to information disclosure.
Invocation of Process Using Visible Sensitive Information
NVIDIA NemoClaw: Credential Exposure Leading to Info Disclosure & Tampering
CVE-2026-65087
5.6 - Medium
- August 25, 2026
NVIDIA NemoClaw contains a vulnerability where an attacker could cause insufficiently protected credentials . A successful exploit of this vulnerability might lead to information disclosure and data tampering.
Insufficiently Protected Credentials
NVIDIA NemoClaw Improper Cert Validation in Deployment Process
CVE-2026-65084
8.1 - High
- August 25, 2026
NVIDIA NemoClaw for Linux contains a vulnerability in its deployment process, where an attacker could cause improper certificate validation. A successful exploit of this vulnerability might lead to information disclosure, data tampering, code execution, and escalation of privileges.
Improper Certificate Validation
Local code injection in NVIDIA NemoClaw Linux migration command
CVE-2026-65082
7 - High
- August 25, 2026
NVIDIA NemoClaw for Linux contains a vulnerability in its migration command, where a local attacker could cause code injection. A successful exploit of this vulnerability might lead to code execution, data tampering, information disclosure, and denial of service.
Code Injection
NVIDIA NemoClaw InstaExec: Untrusted Code Exec Priv Esc
CVE-2026-65081
8.1 - High
- August 25, 2026
NVIDIA NemoClaw for Linux contains a vulnerability in its installation process, where an attacker could cause execution of untrusted code. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, information disclosure, and denial of service.
Download of Code Without Integrity Check
NVIDIA NemoClaw Linux OS Command Injection via Status/Logs Plugin
CVE-2026-65089
7.8 - High
- August 25, 2026
NVIDIA NemoClaw for Linux contains a vulnerability in its status and logs plugin commands, where an attacker could cause OS command injection. A successful exploit of this vulnerability might lead to code execution, data tampering, information disclosure, and denial of service.
Shell injection
NVIDIA NemoClaw NIM OS Command Injection Vulnerability
CVE-2026-65090
7.8 - High
- August 25, 2026
NVIDIA NemoClaw for Linux contains a vulnerability in its NIM management component, where an attacker could cause OS command injection. A successful exploit of this vulnerability might lead to code execution, data tampering, information disclosure, and denial of service.
Shell injection
NVIDIA NemoClaw CLI OS Command Injection
CVE-2026-65099
7.8 - High
- August 25, 2026
NVIDIA NemoClaw for Linux contains a vulnerability in its command-line interface, where an attacker could cause OS command injection. A successful exploit of this vulnerability might lead to code execution, data tampering, information disclosure, and denial of service.
Shell injection
NVIDIA NemoClaw Linux Remote-Access Helper Weak Auth Vulnerability
CVE-2026-65098
8.1 - High
- August 25, 2026
NVIDIA NemoClaw for Linux contains a vulnerability in its remote-access helper workflow, where an attacker could cause weak authentication. A successful exploit of this vulnerability might lead to code execution, information disclosure, and data tampering.
1390
NVIDIA NemoClaw Linux Install Script Lacks Integrity, May Allow Code Exec
CVE-2026-65097
7.5 - High
- August 25, 2026
NVIDIA NemoClaw for Linux contains a vulnerability in its installation scripts, where an attacker could cause a download of code without integrity check. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, information disclosure, and data tampering.
Download of Code Without Integrity Check
NVIDIA NemoClaw OS Cmd Injection via Telegram Bridge (CVE-2026-65096)
CVE-2026-65096
7.8 - High
- August 25, 2026
NVIDIA NemoClaw for Linux contains a vulnerability in the Telegram bridge component, where an attacker could cause an OS command injection. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, information disclosure, and data tampering.
Shell injection
OS Command Injection in NVIDIA NeMo for Linux
CVE-2026-24252
7.8 - High
- July 27, 2026
NVIDIA NeMo for Linux contains a vulnerability where an attacker may cause OS command injection. A successful exploit of this vulnerability may lead to code execution, data tampering, escalation of privileges and information disclosure.
Shell injection
NVIDIA NeMo Framework Deserialization Flaw Enables Remote Code Exec
CVE-2026-24228
7.8 - High
- June 16, 2026
NVIDIA NeMo Framework for Linux contains a vulnerability where an attacker may cause deserialization of untrusted data. A successful exploit of this vulnerability may lead to code execution, escalation of privileges, data tampering, and information disclosure.
Marshaling, Unmarshaling
NVIDIA NeMo Framework Code Injection Vulnerability
CVE-2026-24155
7.8 - High
- June 16, 2026
NVIDIA NeMo Framework for all platforms contains a code injection vulnerability. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, information disclosure, and data tampering.
Code Injection
Path Traversal in Nvidia BioNeMo Core on Linux Enables Code Execution
CVE-2026-24217
8.8 - High
- May 20, 2026
NVIDIA BioNeMo Core for Linux contains a vulnerability where a user could cause a path traversal by loading a malicious file. A successful exploit of this vulnerability might lead to code execution, denial of service, information disclosure, and data tampering.
Path Traversal: '\..\filename'
NVIDIA BioNemo: Deserialization Vulnerability Causing RCE
CVE-2026-24216
7.8 - High
- May 20, 2026
NVIDIA BioNemo for Linux contains a vulnerability where a user could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, denial of service, information disclosure, and data tampering.
Marshaling, Unmarshaling
NVIDIA NemoClaw SSRF via validateEndpointUrl() using 0.0.0.0/8
CVE-2026-24231
6.3 - Medium
- April 28, 2026
NVIDIA NemoClaw contains a vulnerability in the validateEndpointUrl() SSRF protection component, where an attacker could cause a server-side request forgery by supplying a crafted endpoint URL referencing the 0.0.0.0/8 address range through a blueprint configuration file or CLI flag. A successful exploit of this vulnerability may lead to information disclosure.
SSRF
NVIDIA NeMoClaw Sandbox Env. Init: Prompt Injection Leak of Host Vars
CVE-2026-24222
8.6 - High
- April 28, 2026
NVIDIA NeMoClaw contains a vulnerability in the sandbox environment initialization component, where a remote attacker could cause improper access control by sending prompt-injected content that causes the agent to read and exfiltrate host environment variables not properly restricted during sandbox creation. A successful exploit of this vulnerability might lead to information disclosure.
Exposure of Sensitive System Information to an Unauthorized Control Sphere
NVIDIA BioNeMo Untrusted Deserialization CVE-2026-24165
CVE-2026-24165
7.8 - High
- March 31, 2026
NVIDIA BioNeMo contains a vulnerability where a user could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, denial of service, information disclosure, and data tampering.
Marshaling, Unmarshaling
Untrusted Deserialization in NVIDIA BioNeMo Enables RCE
CVE-2026-24164
8.8 - High
- March 31, 2026
NVIDIA BioNeMo contains a vulnerability where a user could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, denial of service, information disclosure, and data tampering.
Marshaling, Unmarshaling
NVIDIA NeMo Framework RCE: Remote Code Execution
CVE-2026-24159
7.8 - High
- March 24, 2026
NVIDIA NeMo Framework contains a vulnerability where an attacker may cause remote code execution. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, information disclosure and data tampering.
Marshaling, Unmarshaling
NVIDIA NeMo Framework RCE via unsafe checkpoint load
CVE-2026-24157
7.8 - High
- March 24, 2026
NVIDIA NeMo Framework contains a vulnerability in checkpoint loading where an attacker could cause remote code execution. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, information disclosure and data tampering.
Marshaling, Unmarshaling
NVIDIA NeMo Framework RCE via Malicious File Load
CVE-2025-33253
7.8 - High
- February 18, 2026
NVIDIA NeMo Framework contains a vulnerability where an attacker could cause remote code execution by convincing a user to load a maliciously crafted file. A successful exploit of this vulnerability might lead to code execution, denial of service, information disclosure, and data tampering.
Marshaling, Unmarshaling
Remote Code Execution in NVIDIA NeMo FW
CVE-2025-33252
7.8 - High
- February 18, 2026
NVIDIA NeMo Framework contains a vulnerability where an attacker could cause remote code execution. A successful exploit of this vulnerability might lead to code execution, denial of service, information disclosure, and data tampering.
Marshaling, Unmarshaling
NVIDIA NeMo Framework RCE Remote Code Execution
CVE-2025-33251
7.8 - High
- February 18, 2026
NVIDIA NeMo Framework contains a vulnerability where an attacker could cause remote code execution. A successful exploit of this vulnerability might lead to code execution, denial of service, information disclosure, and data tampering.
Code Injection
RCE in NVIDIA NeMo Framework
CVE-2025-33250
7.8 - High
- February 18, 2026
NVIDIA NeMo Framework contains a vulnerability where an attacker could cause remote code execution. A successful exploit of this vulnerability might lead to code execution, denial of service, information disclosure, and data tampering.
Code Injection
NVIDIA NeMo Framework Voice-Preproc Script Code Injection
CVE-2025-33249
7.8 - High
- February 18, 2026
NVIDIA NeMo Framework for all platforms contains a vulnerability in a voice-preprocessing script, where malicious input created by an attacker could cause a code injection. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, information disclosure, and data tampering.
Command Injection
NVIDIA NeMo Framework ASR Evaluator Command Injection Vulnerability
CVE-2025-33246
7.8 - High
- February 18, 2026
NVIDIA NeMo Framework for all platforms contains a vulnerability in the ASR Evaluator utility, where a user could cause a command injection by supplying crafted input to a configuration parameter. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, or information disclosure.
Command Injection
NVIDIA NeMo RCE via Malicious Data
CVE-2025-33245
8 - High
- February 18, 2026
NVIDIA NeMo Framework contains a vulnerability where malicious data could cause remote code execution. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, information disclosure, and data tampering.
Marshaling, Unmarshaling
NVIDIA NeMo Framework RCE via Distributed Env Exploit
CVE-2025-33243
7.8 - High
- February 18, 2026
NVIDIA NeMo Framework contains a vulnerability where an attacker could cause remote code execution in distributed environments. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, information disclosure, and data tampering.
Marshaling, Unmarshaling
Remote Code Execution in NVIDIA NeMo via Malicious File (CVE-2025-33241)
CVE-2025-33241
7.8 - High
- February 18, 2026
NVIDIA NeMo Framework contains a vulnerability where an attacker could cause remote code execution by loading a maliciously crafted file. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, information disclosure, and data tampering.
Marshaling, Unmarshaling
NVIDIA NeMo Code Injection Vulnerability (CVE-2025-33236)
CVE-2025-33236
7.8 - High
- February 18, 2026
NVIDIA NeMo Framework contains a vulnerability where malicious data created by an attacker could cause code injection. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, information disclosure, and data tampering.
Code Injection
NVIDIA NeMo Framework Code Injection via Malicious Data
CVE-2025-33226
7.8 - High
- December 16, 2025
NVIDIA NeMo Framework for all platforms contains a vulnerability where malicious data created by an attacker may cause a code injection. A successful exploit of this vulnerability may lead to code execution, escalation of privileges, information disclosure, and data tampering.
Marshaling, Unmarshaling
NVIDIA NeMo Framework: Code Exec from Malicious Model Loading
CVE-2025-33212
7.3 - High
- December 16, 2025
NVIDIA NeMo Framework contains a vulnerability in model loading that could allow an attacker to exploit improper control mechanisms if a user loads a maliciously crafted file. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, denial of service, and data tampering.
Marshaling, Unmarshaling
NVIDIA NeMo Agent Toolkit UI: SSRF in Chat API
CVE-2025-33203
7.6 - High
- November 25, 2025
NVIDIA NeMo Agent Toolkit UI for Web contains a vulnerability in the chat API endpoint where an attacker may cause a Server-Side Request Forgery. A successful exploit of this vulnerability may lead to information disclosure and denial of service.
SSRF
NVIDIA NeMo: Predefined Variable Inclusion Allows Code Exec
CVE-2025-33205
7.3 - High
- November 25, 2025
NVIDIA NeMo framework contains a vulnerability in a predefined variable, where an attacker could cause inclusion of functionality from an untrusted control sphere by use of a predefined variable. A successful exploit of this vulnerability may lead to code execution.
Inclusion of Functionality from Untrusted Control Sphere
NVIDIA NeMo Framework Code Injection via Malicious NLP/LLM Data
CVE-2025-33204
7.8 - High
- November 25, 2025
NVIDIA NeMo Framework for all platforms contains a vulnerability in the NLP and LLM components, where malicious data created by an attacker could cause code injection. A successful exploit of this vulnerability may lead to code execution, escalation of privileges, information disclosure, and data tampering.
Code Injection
NVIDIA NeMo BERT Services Code Injection (CVE-2025-33178)
CVE-2025-33178
7.8 - High
- November 11, 2025
NVIDIA NeMo Framework for all platforms contains a vulnerability in the bert services component where malicious data created by an attacker may cause a code injection. A successful exploit of this vulnerability may lead to Code execution, Escalation of privileges, Information disclosure, and Data tampering.
Code Injection
NVIDIA NeMo Framework Improper Code Gen via Script Input (CVE-2025-23361)
CVE-2025-23361
7.8 - High
- November 11, 2025
NVIDIA NeMo Framework for all platforms contains a vulnerability in a script, where malicious input created by an attacker may cause improper control of code generation. A successful exploit of this vulnerability may lead to code execution, escalation of privileges, information disclosure, and data tampering.
Code Injection
CVE-2025-23251: RCE via Improper Generated Code Control in NVIDIA NeMo
CVE-2025-23251
7.6 - High
- April 22, 2025
NVIDIA NeMo Framework contains a vulnerability where a user could cause an improper control of generation of code by remote code execution. A successful exploit of this vulnerability might lead to code execution and data tampering.
Code Injection
NVIDIA NeMo Framework Deserialization RCE Enables Code Execution
CVE-2025-23249
7.6 - High
- April 22, 2025
NVIDIA NeMo Framework contains a vulnerability where a user could cause a deserialization of untrusted data by remote code execution. A successful exploit of this vulnerability might lead to code execution and data tampering.
Marshaling, Unmarshaling
NVIDIA NeMo: Improper Pathname Limitation Allows Arbitrary File Write
CVE-2025-23250
7.6 - High
- April 22, 2025
NVIDIA NeMo Framework contains a vulnerability where an attacker could cause an improper limitation of a pathname to a restricted directory by an arbitrary file write. A successful exploit of this vulnerability might lead to code execution and data tampering.
Directory traversal
NVIDIA NeMo Path Traversal via Unsafe .tar Extraction in SaveRestoreConnector
CVE-2024-0129
7.8 - High
- October 15, 2024
NVIDIA NeMo contains a vulnerability in SaveRestoreConnector where a user may cause a path traversal issue via an unsafe .tar file extraction. A successful exploit of this vulnerability may lead to code execution and data tampering.
Directory traversal
NVIDIA NeMo before 1.6.0 contains a vulnerability in ASR WebApp, in which
CVE-2022-22821
4.4 - Medium
- January 10, 2022
NVIDIA NeMo before 1.6.0 contains a vulnerability in ASR WebApp, in which ../ Path Traversal may lead to deletion of any directory when admin privileges are available.
Directory traversal
Stay on top of Security Vulnerabilities
Want an email whenever new vulnerabilities are published for NVIDIA Nemo or by NVIDIA? Click the Watch button to subscribe.