nemo-toolkit
PyPI5 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting nemo-toolkitpage 1 of 1
- CVE-2022-22821LOWCVSS 2.0EG 2.0✓ Fixed in 1.6.02022-01-10
vulnerable: 0.10.0 ... 1.5.1 (44 versions)
NVIDIA NeMo before 1.6.0 contains a vulnerability in ASR WebApp, in which ../ Path Traversal may lead to deletion of any directory when admin privileges are available.
- CVE-2025-33245HIGHCVSS 8.8EG 8.8✓ Fixed in 2.6.12026-02-18
vulnerable: 0.10.0 ... 2.6.0rc0 (102 versions)
NVIDIA NeMo Framework contains a vulnerability where malicious data could cause remote code execution. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, information disclosure, and data tamp…
- CVE-2025-33253HIGHCVSS 7.3EG 7.3✓ Fixed in 2.6.12026-02-18
vulnerable: 0.10.0 ... 2.6.0rc0 (102 versions)
NVIDIA NeMo Framework contains a vulnerability where an attacker could cause remote code execution by convincing a user to load a maliciously crafted file. A successful exploit of this vulnerability might lead to code execution, denial of …
- CVE-2026-24157CRITICALCVSS 9.8EG 9.8✓ Fixed in 2.6.22026-03-24
vulnerable: 0.10.0 ... 2.6.1 (103 versions)
NVIDIA NeMo Framework contains a vulnerability in checkpoint loading where an attacker could cause remote code execution. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, information disclo…
- CVE-2026-24159CRITICALCVSS 9.8EG 9.8✓ Fixed in 2.6.22026-03-24
vulnerable: 0.10.0 ... 2.6.1 (103 versions)
NVIDIA NeMo Framework contains a vulnerability where an attacker may cause remote code execution. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, information disclosure and data tampering.
Check whether nemo-toolkit is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for nemo-toolkit CVEs against the assets you own.
Start Free Scan →