Description
NVIDIA TAO contains a vulnerability where an attacker may cause a resource to be loaded via an uncontrolled search path. A successful exploit of this vulnerability may lead to escalation of privileges, data tampering, denial of service, information disclosure.
Published: 2025-12-03
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

No vendor fix or workaround currently provided.

Additional remediation guidance may be available on OpenCVE Cloud.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 30 Jan 2026 18:45:00 +0000

Type Values Removed Values Added
First Time appeared Canonical
Canonical ubuntu Linux
Nvidia tao Toolkit
CPEs cpe:2.3:a:nvidia:tao_toolkit:6.25.7:*:*:*:*:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:-:*:*:*:lts:*:*:*
Vendors & Products Canonical
Canonical ubuntu Linux
Nvidia tao Toolkit

Thu, 04 Dec 2025 16:45:00 +0000

Type Values Removed Values Added
First Time appeared Nvidia
Nvidia tao
Vendors & Products Nvidia
Nvidia tao

Wed, 03 Dec 2025 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 03 Dec 2025 18:30:00 +0000

Type Values Removed Values Added
Description NVIDIA TAO contains a vulnerability where an attacker may cause a resource to be loaded via an uncontrolled search path. A successful exploit of this vulnerability may lead to escalation of privileges, data tampering, denial of service, information disclosure.
Weaknesses CWE-427
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}


Subscriptions

Canonical Ubuntu Linux
Nvidia Tao Tao Toolkit
cve-icon MITRE

Status: PUBLISHED

Assigner: nvidia

Published:

Updated: 2025-12-03T18:55:47.516Z

Reserved: 2025-04-15T18:51:06.122Z

Link: CVE-2025-33208

cve-icon Vulnrichment

Updated: 2025-12-03T18:55:35.076Z

cve-icon NVD

Status : Analyzed

Published: 2025-12-03T19:15:55.983

Modified: 2026-01-30T18:41:29.603

Link: CVE-2025-33208

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2025-12-04T16:43:57Z

Weaknesses