{"id":"CVE-2025-33228","details":"NVIDIA Nsight Systems contains a vulnerability in the gfx_hotspot recipe, where an attacker could cause an OS command injection by supplying a malicious string to the process_nsys_rep_cli.py script if the script is invoked manually. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, denial of service, and information disclosure.","modified":"2026-03-14T12:43:08.027699Z","published":"2026-01-20T18:16:02.300Z","references":[{"type":"ADVISORY","url":"https://www.cve.org/CVERecord?id=CVE-2025-33228"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-33228"},{"type":"FIX","url":"https://nvidia.custhelp.com/app/answers/detail/a_id/5755"}],"affected":[{"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-33228.json","unresolved_ranges":[{"events":[{"introduced":"0"},{"fixed":"13.1.0"}]}]}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H"}]}