A critical deserialization vulnerability (CVE-2025-32210) was discovered in NVIDIA Isaac Lab, a component of the NVIDIA Isaac Sim framework, allowing attackers with low privileges and minimal user interaction to execute arbitrary code on affected systems. The flaw, categorized as CWE-502, affects all versions of Isaac Lab prior to v2.3.0 and carries a CVSS score of 9.0, indicating a high risk to confidentiality, integrity, and availability. NVIDIA responded by releasing a security update that implements proper input validation and secure data handling, urging all users to upgrade to Isaac Lab v2.3.0 immediately to mitigate the risk of exploitation.
The vulnerability also prompted broader advisories regarding critical security patches for NVIDIA's AI platforms, including both Isaac Lab and the NeMo Framework, due to the risk of full code execution if left unpatched. Organizations using these AI tools are strongly advised to verify their deployments and apply the latest security updates across all environments. The urgency of the patch is underscored by the potential for attackers to achieve complete system compromise through network-based attacks requiring only low-level access and user interaction.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
NVIDIA publicly disclosed critical vulnerabilities affecting its Isaac Lab and NeMo Framework AI platforms, warning that the flaws could enable full code execution on affected systems. The company advised organizations to apply patches immediately to reduce exploitation risk.
NVIDIA released Isaac Lab v2.3.0 to address CVE-2025-32210 by improving input validation and secure data handling. The vulnerability affected all Isaac Lab versions prior to v2.3.0 and carried a CVSS score of 9.0.
Daniel Teixeira of the NVIDIA AI Red Team responsibly reported a deserialization of untrusted data vulnerability in NVIDIA Isaac Lab, later assigned CVE-2025-32210. The flaw could allow low-privileged attackers with minimal user interaction to execute arbitrary code.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.