CVE-2025-33251: Code Injection
Published Feb 18, 2026
·Updated
NVIDIA NeMo Framework contains a vulnerability where an attacker could cause remote code execution. A successful exploit of this vulnerability might lead to code execution, denial of service, information disclosure, and data tampering.
Affected Software
1 affected component
Nvidia NeMo<2.6.1
Event History
Feb 18, 2026
CVE Published
via MITRE·01:56 PM
Data Sourced
via MITRE·01:56 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·02:16 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-33251?
CVE-2025-33251 is classified as a critical vulnerability that can lead to remote code execution.
2
How do I fix CVE-2025-33251?
To remediate CVE-2025-33251, you should update your NVIDIA NeMo Framework to version 2.6.1 or later.
3
What types of attacks can CVE-2025-33251 facilitate?
CVE-2025-33251 can facilitate remote code execution, denial of service, information disclosure, and data tampering.
4
Which versions of NVIDIA NeMo are affected by CVE-2025-33251?
NVIDIA NeMo versions prior to 2.6.1 are affected by CVE-2025-33251.
5
Can CVE-2025-33251 be exploited without user interaction?
Yes, CVE-2025-33251 can be exploited remotely without any user interaction.