PT-2025-47348 · Nvidia · Nvidia Isaac-Gr00T

Published

2025-11-18

·

Updated

2025-12-07

·

CVE-2025-33183

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions NVIDIA Isaac-GR00T (affected versions not specified)
Description The NVIDIA Isaac-GR00T robotics platform contains a flaw related to improper code generation management. Exploitation of this issue could allow a remote attacker to execute arbitrary code, escalate privileges, and gain unauthorized access to protected information. The issue resides within a Python component and involves a code injection vulnerability specifically related to TorchSerializer deserialization of untrusted data. A successful exploit may lead to code execution, privilege escalation, information disclosure, and data tampering.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

LPE

RCE

Code Injection

Weakness Enumeration

Related Identifiers

BDU:2025-14730
CVE-2025-33183
ZDI-25-1041

Affected Products

Nvidia Isaac-Gr00T