Skip to content
NvidiaCVE-2026-24252

Nvidia NeMo Framework: command injection

High7.8CVE-2026-24252 · Published Jul 27, 2026 · updated Sep 4, 2026

NVIDIA NeMo for Linux contains a vulnerability where an attacker may cause OS command injection. A successful exploit of this vulnerability may lead to code execution, data tampering, escalation of privileges and information disclosure.

Nvidia advisory

Affected versions

PackageAffectedFixed in
NeMo Framework
Product
<= Versions 0.0 to 2.7.2No fix yet
Details and references
CVSS 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Severity from
the vendor (its own CVE record or advisory)
Weakness
CWE-78

More Nvidia advisories

All Nvidia
Advisory
Nvidia Dynamo: server-side request forgery
High7.5Aug 4
Nvidia Dynamo: server-side request forgery
High7.5Aug 4
Nvidia Dynamo: out-of-bounds write
Critical9.8Aug 4
Nvidia Dynamo: out-of-bounds write
High8.2Aug 4
Nvidia DCGM: resource exhaustion
High8.2Jul 28
Nvidia Tranformers4Rec: unsafe deserialization
Medium4.3Jul 21

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.