PYSEC-2026-2675

See a problem?
Import Source
https://github.com/pypa/advisory-database/blob/main/vulns/nemo-toolkit/PYSEC-2026-2675.yaml
JSON Data
https://api.osv.dev/v1/vulns/PYSEC-2026-2675
Aliases
Published
2026-07-13T14:36:44Z
Modified
2026-07-13T16:32:48Z
Severity
  • 7.8 (High) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
NVIDIA NeMo Framework contains a vulnerability leading to Remote Code Execution
Details

NVIDIA NeMo Framework contains a vulnerability where an attacker may cause remote code execution. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, information disclosure and data tampering.

References

Affected packages

PyPI / nemo-toolkit

Package

Name
nemo-toolkit
View open source insights on deps.dev
Purl
pkg:pypi/nemo-toolkit

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
2.6.2

Affected versions

0.*
0.8
0.8.1
0.8.2
0.9.0
0.10.0b0
0.10.0b1
0.10.0b2
0.10.0b3
0.10.0b4
0.10.0b5
0.10.0b6
0.10.0b7
0.10.0b8
0.10.0b9
0.10.0b10
0.10.0
0.10.1
0.11.0b1
0.11.0b2
0.11.0b3
0.11.0b4
0.11.0b5
0.11.0b6
0.11.0b8
0.11.0b10
0.11.0b11
0.11.0b12
0.11.0b14
0.11.0
1.*
1.0.0a4
1.0.0b0
1.0.0b1
1.0.0b2
1.0.0b3
1.0.0rc1
1.0.0
1.0.1
1.0.2
1.1.0
1.2.0
1.3.0
1.4.0
1.5.0
1.5.1
1.6.0
1.6.1
1.6.2
1.7.0
1.7.1
1.7.2
1.8.0
1.8.1
1.8.2
1.9.0
1.10.0
1.11.0
1.12.0
1.13.0
1.14.0
1.15.0
1.16.0
1.17.0
1.18.0
1.18.1
1.19.0
1.19.1
1.20.0
1.21.0
1.22.0
1.23.0
2.*
2.0.0rc0
2.0.0rc1
2.0.0
2.1.0rc0
2.1.0rc1
2.1.0rc2
2.1.0
2.2.0rc0
2.2.0rc1
2.2.0rc2
2.2.0rc3
2.2.0
2.2.1
2.3.0rc2
2.3.0rc3
2.3.0rc4
2.3.0
2.3.1
2.3.2
2.3.3
2.4.0rc0
2.4.0rc1
2.4.0rc2
2.4.0
2.4.1
2.5.0rc0
2.5.0
2.5.1
2.5.2
2.5.3
2.6.0rc0
2.6.0
2.6.1

Database specific

source
"https://github.com/pypa/advisory-database/blob/main/vulns/nemo-toolkit/PYSEC-2026-2675.yaml"