VYPR
High severity7.8NVD Advisory· Published Nov 18, 2025· Updated Apr 15, 2026

CVE-2025-33183

CVE-2025-33183

Description

NVIDIA Isaac-GR00T for all platforms contains a vulnerability in a Python component, where an attacker could cause a code injection issue. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, information disclosure, and data tampering.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

NVIDIA Isaac-GR00T contains a code injection vulnerability in a Python component, enabling code execution, privilege escalation, info disclosure, and data tampering.

Vulnerability

Overview

CVE-2025-33183 is a code injection vulnerability in a Python component of NVIDIA Isaac-GR00T affecting all platforms. The root cause stems from improper handling of user input within the Python component, allowing an attacker to inject arbitrary code. This flaw can be triggered without authentication requirements in certain attack scenarios, depending on the deployment context.

Exploitation

Details

An attacker can exploit this vulnerability by providing crafted input to the affected Python component. The attack vector may be local or remote, depending on how the component is exposed. No user interaction is needed for exploitation beyond the initial injection point. The vulnerability does not require high privileges to exploit, making it accessible to attackers with low access levels [1].

Impact

Assessment

Successful exploitation could lead to full code execution on the target system, enabling the attacker to escalate privileges, access sensitive information, and tamper with data. This could result in complete compromise of the confidentiality, integrity, and availability of the affected system [1].

Mitigation

Status

As of publication, NVIDIA has not released a patch for this vulnerability. Users are advised to follow NVIDIA's security recommendations and monitor official channels for updates. Until a fix is available, limiting access to the Python component and applying least privilege principles may reduce risk.

AI Insight generated on May 19, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

3

News mentions

1