Description
NVIDIA NeMo Framework for all platforms contains a vulnerability in the ASR Evaluator utility, where a user could cause a command injection by supplying crafted input to a configuration parameter. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, or information disclosure.
Problem types
CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection')
Product status
All versions prior to 2.6.1
References
nvd.nist.gov/vuln/detail/CVE-2025-33246
www.cve.org/CVERecord?id=CVE-2025-33246
nvidia.custhelp.com/app/answers/detail/a_id/5762