NeMo Framework: Remote RCE via insecure deserialization over the network
CVE-2025-33245NVIDIA / GPU stackcurated
Impact
Remote RCE via insecure deserialization over the network
Who can reach it
Network attacker feeding a serialized payload
What to do
Bump NeMo; rebuild and redeploy; restrict network exposure of NeMo services
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.