NVIDIA NeMo Agent Toolkit UI for Web contains a vulnerability in the chat API endpoint where an attacker may cause a Server-Side Request Forgery. A successful exploit of this vulnerability may lead to information disclosure and denial of service.
Metrics
Affected Vendors & Products
References
History
Thu, 27 Nov 2025 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Nvidia
Nvidia nemo |
|
| Vendors & Products |
Nvidia
Nvidia nemo |
Wed, 26 Nov 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 25 Nov 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | NVIDIA NeMo Agent Toolkit UI for Web contains a vulnerability in the chat API endpoint where an attacker may cause a Server-Side Request Forgery. A successful exploit of this vulnerability may lead to information disclosure and denial of service. | |
| Weaknesses | CWE-918 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: nvidia
Published: 2025-11-25T18:10:33.659Z
Updated: 2025-11-26T15:58:54.292Z
Reserved: 2025-04-15T18:51:05.243Z
Link: CVE-2025-33203
Updated: 2025-11-26T15:58:51.378Z
Status : Awaiting Analysis
Published: 2025-11-25T18:15:52.200
Modified: 2025-11-25T22:16:16.690
Link: CVE-2025-33203
No data.