CVE-2025-33184
7.8NVIDIA · Isaac-GR00T
NVIDIA Isaac-GR00T is affected by a code injection vulnerability within a Python component that may allow an authenticated local attacker to execute arbitrary code.
Executive summary
A critical code injection vulnerability in NVIDIA Isaac-GR00T allows local attackers to achieve arbitrary code execution and system compromise.
Vulnerability
The software contains a code injection flaw (CWE-94) in a Python component. According to the CVSS vector (PR:L), this vulnerability requires a local attacker with low privileges to trigger the issue.
Business impact
Successful exploitation of this vulnerability can lead to full system compromise, including privilege escalation, information disclosure, and unauthorized data tampering. With a CVSS score of 7.8, the vulnerability poses a high risk to the confidentiality, integrity, and availability of the affected system, potentially disrupting development workflows or exposing proprietary robotic simulation data.
Remediation
Immediate Action: Update the affected software to a version that includes the fix provided in code commit 7f53666 as detailed in the vendor security advisory.
Proactive Monitoring: Review system access logs for signs of unauthorized local execution or unexpected modifications to Python scripts and environment configurations.
Compensating Controls: Restrict local system access to authorized personnel only and enforce the principle of least privilege to minimize the potential for an attacker to leverage low-level access for exploitation.
Exploitation status
Public Exploit Available: No
Analyst recommendation
Given the severity of the potential impact, organizations utilizing NVIDIA Isaac-GR00T should prioritize verifying their current version against the specified code commit. Apply the necessary vendor-supplied updates immediately to remediate the code injection risk and ensure the security of the development environment.