Skip to content
NVIDIA NeMo Framework Vulnerable to High-Severity Command Injection Flaws

NVIDIA NeMo Framework Vulnerable to High-Severity Command Injection Flaws

First seen 17 Jun 2026, 18:57 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster June 18, 2026 at 18:53 UTC
  • NVIDIA disclosed three high-severity vulnerabilities in the NeMo Framework.
  • The vulnerabilities allow command injection and privilege escalation on affected systems.
  • A patched version, NeMo 2.7.3, is available, and users are urged to update.

NVIDIA disclosed three high-severity vulnerabilities in the NeMo Framework, tracked as CVE-2026-24155, CVE-2026-24252, and CVE-2026-24228, each with a CVSS score of 7.8. The vulnerabilities affect all platforms, with CVE-2026-24252 specifically impacting Linux deployments, allowing OS command injection. Attackers with low privileges and local access can exploit these flaws to execute system commands, manipulate data, and escalate privileges. Affected versions include NeMo up to 2.7.2, with a patched release, NeMo 2.7.3, now available. There are currently no reports of active exploitation of these vulnerabilities. The vulnerabilities stem from improper handling of user-controlled input and unsafe deserialization of untrusted data. Security teams are advised to update to the patched version to mitigate risks.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 93d ago How this analysis works

Timeline

2026-06-12
NVIDIA updates security bulletin
NVIDIA released a security bulletin detailing three high-severity vulnerabilities in NeMo Framework.
Letsdatascience
2026-06-16
CVE-2026-24155 and CVE-2026-24228 published
CVE-2026-24155 and CVE-2026-24228 were published, confirming their high severity and impact.
Letsdatascience
2026-06-16
CVE-2026-24252 published
CVE-2026-24252 was published, detailing OS command injection vulnerabilities in Linux deployments.
Letsdatascience
2026-06-17
NeMo 2.7.3 released
NVIDIA released NeMo 2.7.3, which addresses the identified vulnerabilities and is recommended for users.
Heise.De

More articles in this cluster (2)

Following this threat?

Track Nvidia and CVE-2026-24155 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed