CVE-2025-33203: NVIDIA Nemo Agent Toolkit

High severity, CVSS 7.6. EPSS: 0.3% chance of exploitation in the next 30 days.

NVIDIA NeMo Agent Toolkit UI for Web contains a vulnerability in the chat API endpoint where an attacker may cause a Server-Side Request Forgery. A successful exploit of this vulnerability may lead to information disclosure and denial of service.

Affected products

  • NVIDIA Nemo Agent Toolkit: before 1.3.0 (fixed in 1.3.0)

Published 2025-11-25. Last modified 2026-06-17.