CVE-2025-23304

NVIDIA NeMo library for all platforms contains a vulnerability in the model loading component, where an attacker could cause code injection by loading .nemo files with maliciously crafted metadata. A successful exploit of this vulnerability may lead to remote code execution and data tampering.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:a:nvidia:nemo:*:*:*:*:*:*:*:*
OR cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*

History

23 Sep 2025, 23:17

Type Values Removed Values Added
First Time Apple macos
Linux linux Kernel
Apple
Nvidia nemo
Microsoft
Microsoft windows
Linux
Nvidia
CPE cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
cpe:2.3:a:nvidia:nemo:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:*
References () https://nvd.nist.gov/vuln/detail/CVE-2025-23304 - () https://nvd.nist.gov/vuln/detail/CVE-2025-23304 - US Government Resource
References () https://nvidia.custhelp.com/app/answers/detail/a_id/5686 - () https://nvidia.custhelp.com/app/answers/detail/a_id/5686 - Vendor Advisory
References () https://www.cve.org/CVERecord?id=CVE-2025-23304 - () https://www.cve.org/CVERecord?id=CVE-2025-23304 - Third Party Advisory
CWE CWE-94

14 Aug 2025, 13:12

Type Values Removed Values Added
Summary
  • (es) La librería NVIDIA NeMo para todas las plataformas contiene una vulnerabilidad en el componente de carga de modelos, donde un atacante podría inyectar código manipulando archivos .nemo con metadatos maliciosos. Explotar esta vulnerabilidad podría provocar la ejecución remota de código y la manipulación de datos.

13 Aug 2025, 18:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-08-13 18:15

Updated : 2025-09-24 13:13


NVD link : CVE-2025-23304

Mitre link : CVE-2025-23304

CVE.ORG link : CVE-2025-23304


JSON object : View

Products Affected

apple

  • macos

linux

  • linux_kernel

microsoft

  • windows

nvidia

  • nemo
CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

CWE-94

Improper Control of Generation of Code ('Code Injection')