Skip to main content
CVE Vulnerability Database
Vulnerability Database/CVE-2025-33178

CVE-2025-33178: Nvidia Nemo Framework RCE Vulnerability

CVE-2025-33178 is a code injection flaw in Nvidia Nemo Framework's bert services component that enables remote code execution. Attackers can exploit this to execute code, escalate privileges, and access sensitive data.

Published:

CVE-2025-33178 Overview

CVE-2025-33178 is a code injection vulnerability in the NVIDIA NeMo Framework, affecting the bert services component across all supported platforms. An attacker with local, low-privilege access can supply crafted malicious data that the component processes unsafely, resulting in arbitrary code execution in the context of the NeMo process.

Successful exploitation enables code execution, privilege escalation, information disclosure, and data tampering within the affected environment. The weakness maps to CWE-94: Improper Control of Generation of Code.

Critical Impact

Local attackers can execute arbitrary code inside the NeMo Framework process, compromise model integrity, exfiltrate training data, and escalate privileges on affected hosts.

Affected Products

  • NVIDIA NeMo Framework (all platforms) — see the NVIDIA Support Article for fixed versions
  • Systems running the NeMo bert services component
  • Machine learning pipelines and training hosts that ingest untrusted data through NeMo

Discovery Timeline

  • 2025-11-11 - CVE-2025-33178 published to the National Vulnerability Database
  • 2026-06-17 - Last updated in NVD database

Technical Details for CVE-2025-33178

Vulnerability Analysis

The vulnerability resides in the bert services component of the NVIDIA NeMo Framework, an open-source toolkit for building and training large language models and conversational AI. The component processes input data in a manner that allows attacker-controlled content to be interpreted as executable code rather than data.

Exploitation requires local access and low privileges. No user interaction is required. Because the attack executes within the NeMo process context, it produces high impact to confidentiality, integrity, and availability. An attacker who controls training inputs, configuration files, or intermediate artifacts consumed by bert services can pivot from data supplier to code executor on the host.

Root Cause

The root cause is improper control of code generation ([CWE-94]). The bert services component fails to safely separate untrusted input from code constructs during processing. Consult the NVIDIA Support Article for the vendor's description of the affected code paths and remediated versions.

Attack Vector

The attack vector is local. A user or process with low privileges on a host running NeMo submits crafted input, such as a poisoned dataset, configuration, or serialized artifact, to the bert services component. When the component processes the input, the embedded payload executes with the privileges of the NeMo service. From there, the attacker can read sensitive files, modify model weights and training data, install persistence, or attempt privilege escalation on the underlying host.

No public proof-of-concept is available. The EPSS score is low, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog.

Detection Methods for CVE-2025-33178

Indicators of Compromise

  • Unexpected child processes spawned by NeMo Framework or Python interpreters running BERT services
  • Modification of model checkpoints, tokenizer files, or training configurations outside of scheduled pipeline windows
  • Outbound network connections from GPU or ML training hosts to previously unseen destinations
  • New or altered files in NeMo working directories with executable content or serialized Python objects from untrusted sources

Detection Strategies

  • Baseline the process tree for NeMo workloads and alert on deviations, including shell interpreters spawned from Python training jobs
  • Enable audit logging on directories that store BERT service inputs, datasets, and configuration files, and correlate write events with pipeline identity
  • Inspect logs from the bert services component for parsing errors, unexpected imports, or runtime exceptions that may indicate injection attempts

Monitoring Recommendations

  • Forward host, container, and Kubernetes audit logs from ML training infrastructure to a centralized analytics platform for correlation
  • Monitor GPU workload hosts for privilege escalation attempts, credential access, and lateral movement following any anomalous NeMo activity
  • Track integrity of model artifacts and datasets using cryptographic hashes recorded before and after each training run

How to Mitigate CVE-2025-33178

Immediate Actions Required

  • Apply the fixed NeMo Framework release identified in the NVIDIA Support Article to all training and inference hosts
  • Inventory systems running NVIDIA NeMo and identify any exposure of the bert services component to multi-tenant or shared environments
  • Restrict local access to NeMo hosts to a minimum set of trusted operators and service accounts
  • Review recent training jobs and datasets for signs of tampering or unauthorized submissions

Patch Information

NVIDIA has published remediation guidance in the vendor advisory. Refer to the NVIDIA Support Article a_id/5718 for fixed versions and upgrade instructions. Additional metadata is available in the NVD CVE-2025-33178 Detail and CVE.org Record.

Workarounds

  • Isolate NeMo workloads in dedicated containers or virtual machines with least-privilege service accounts to limit blast radius
  • Validate and sanitize all datasets, configurations, and serialized artifacts before they are consumed by bert services, and reject inputs from untrusted sources
  • Disable or restrict the bert services component in environments where it is not required until patching is complete
  • Enforce role-based access control and MFA on the systems and repositories that supply data to NeMo pipelines

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.