CVE-2025-33183

7.8

NVIDIA · Isaac-GR00T

NVIDIA Isaac-GR00T is susceptible to a code injection vulnerability within a Python component, potentially allowing an attacker to execute arbitrary code.

Executive summary

A critical code injection vulnerability in NVIDIA Isaac-GR00T may allow an attacker with local, low-level privileges to achieve full system compromise.

Vulnerability

This flaw involves improper control of code generation (CWE-94) within a Python component, which an attacker with local access and low privileges can exploit to facilitate arbitrary code execution, privilege escalation, information disclosure, and data tampering.

Business impact

The potential for unauthorized code execution poses a severe risk to organizational data integrity and system availability. Given the CVSS score of 7.8, this vulnerability is classified as High, as it provides a pathway for a local attacker to bypass security controls and gain full control over the affected Isaac-GR00T environment, leading to potential intellectual property theft or service disruption.

Remediation

Immediate Action: Update to the version containing the fix identified by the vendor, specifically ensuring the environment incorporates code commit 7f53666.

Proactive Monitoring: Monitor system logs for unexpected Python script executions or unusual process spawning behaviors originating from the Isaac-GR00T component.

Compensating Controls: Restrict local access to the systems running the affected software to authorized personnel only, as the vulnerability requires local access to trigger.

Exploitation status

Public Exploit Available: No

Analyst recommendation

Organizations utilizing NVIDIA Isaac-GR00T must prioritize the application of the vendor-provided security update. Because this vulnerability allows for code execution and privilege escalation, failure to remediate exposes the host system to significant risk of total compromise. Ensure that all deployment environments are verified against the specified fix commit to confirm the vulnerability is fully mitigated.

More NVIDIA CVEs

Sources