CVE-2025-33203: NVIDIA Nemo Agent Toolkit
High severity, CVSS 7.6. EPSS: 0.3% chance of exploitation in the next 30 days.
NVIDIA NeMo Agent Toolkit UI for Web contains a vulnerability in the chat API endpoint where an attacker may cause a Server-Side Request Forgery. A successful exploit of this vulnerability may lead to information disclosure and denial of service.
Affected products
- NVIDIA Nemo Agent Toolkit: before 1.3.0 (fixed in 1.3.0)
Published 2025-11-25. Last modified 2026-06-17.