CVE ID: CVE-2025-33203 Published Date: 2025-11-25 Updated Date: 2025-11-25 Description: The NVIDIA NeMo Agent Toolkit UI for Web has a vulnerability in the chat API endpoint that could allow a Server-Side Request Forgery (SSRF). A successful exploit could lead to information disclosure and denial of service. CWE: CWE-918: Server-Side Request Forgery (SSRF) CVSS: - Score: 7.6 - Severity: HIGH - Version: 3.1 - Vector String: AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:L Product Status: - Vendor: NVIDIA - Product: NeMo Agent ToolKit - Platforms: All platforms - Affected Versions: All versions prior to 1.3.0 References: - https://nvd.nist.gov/vuln/detail/CVE-2025-33203 - https://www.cve.org/CVERecord?id=CVE-2025-33203 - https://nvidia.custhelp.com/app/answers/detail/a_id/5726