NVIDIA Isaac Lab Flaw Enables Remote Code Execution
NVIDIA has identified a critical security vulnerability in Isaac Lab, a component of the NVIDIA Isaac Sim framework, which allows for remote code execution.
NVIDIA has identified a critical security vulnerability in Isaac Lab, a component of the NVIDIA Isaac Sim framework, which allows for remote code execution.
Security patches were released in December 2025 to address the deserialization flaw identified as CVE-2025-32210.
CVE ID Description CVSS Score Severity CWE
CVE-2025-32210 Deserialization vulnerability in NVIDIA Isaac Lab 9.0 Critical CWE-502
Critical Deserialization Vulnerability
The vulnerability is due to improper deserialization in NVIDIA Isaac Lab, enabling code execution on affected systems when exploited. With a CVSS score of 9.0, it is deemed critical, posing significant risks to organizations using the simulation framework.
The attack vector requires network access with low attack complexity. Exploitation necessitates low-level privileges and user interaction, but the scope can extend beyond the vulnerable component, potentially impacting confidentiality, integrity, and availability.
Security patches were released in December 2025 to address the deserialization flaw identified as CVE-2025-32210.
All versions of Isaac Lab before v2.3.0 are susceptible to CVE-2025-32210.
NVIDIA recommends immediate updates to Isaac Sim v2.3.0, which includes security fixes for this flaw. Organizations using earlier versions should prioritize patching, as remote code execution vulnerabilities provide extensive control to attackers.
The vulnerability could lead to data theft, system manipulation, or the deployment of additional malicious payloads.
This issue was discovered and responsibly disclosed by Daniel Teixeira from NVIDIA's AI Red Team.
NVIDIA's Product Security Incident Response Team (PSIRT) released a security bulletin on December 2, 2025, providing detailed vulnerability information and remediation guidance.
Users should download the latest Isaac Lab version from the official GitHub repository and ensure all installations are updated to v2.3.0 or later.
NVIDIA advises subscribing to security bulletin notifications through their Product Security page to remain informed about future vulnerabilities and patches.
Based on reporting by GBHackers.
