NVIDIA NeMo Framework Vulnerable to High-Severity Command Injection Flaws

NVIDIA NeMo Framework Vulnerable to High-Severity Command Injection Flaws

First seen 17 Jun 2026, 18:57 UTC LetsdatascienceHeise.De 77% similarity 72.5

Article Content

Browse articles
ThreatCluster

NVIDIA disclosed three high-severity vulnerabilities in the NeMo Framework, tracked as CVE-2026-24155, CVE-2026-24252, and CVE-2026-24228, each with a CVSS score of 7.8. The vulnerabilities affect all platforms, with CVE-2026-24252 specifically impacting Linux deployments, allowing OS command injection. Attackers with low privileges and local access can exploit these flaws to execute system commands, manipulate data, and escalate privileges. Affected versions include NeMo up to 2.7.2, with a patched release, NeMo 2.7.3, now available. There are currently no reports of active exploitation of these vulnerabilities. The vulnerabilities stem from improper handling of user-controlled input and unsafe deserialization of untrusted data. Security teams are advised to update to the patched version to mitigate risks.

Key Points: • NVIDIA disclosed three high-severity vulnerabilities in the NeMo Framework. • The vulnerabilities allow command injection and privilege escalation on affected systems. • A patched version, NeMo 2.7.3, is available, and users are urged to update.

ThreatCluster AI How this analysis works

Timeline

2026-06-12
NVIDIA updates security bulletin
NVIDIA released a security bulletin detailing three high-severity vulnerabilities in NeMo Framework.
Letsdatascience
2026-06-16
CVE-2026-24155 and CVE-2026-24228 published
CVE-2026-24155 and CVE-2026-24228 were published, confirming their high severity and impact.
Letsdatascience
2026-06-16
CVE-2026-24252 published
CVE-2026-24252 was published, detailing OS command injection vulnerabilities in Linux deployments.
Letsdatascience
2026-06-17
NeMo 2.7.3 released
NVIDIA released NeMo 2.7.3, which addresses the identified vulnerabilities and is recommended for users.
Heise.De

Community

Browse all →

Tracked Entities in This Story