CVE-2025-23304

NVIDIA NeMo library for all platforms contains a vulnerability in the model loading component, where an attacker could cause code injection by loading .nemo files with maliciously crafted metadata. A successful exploit of this vulnerability may lead to remote code execution and data tampering.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:a:nvidia:nemo:*:*:*:*:*:*:*:*
OR cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*

History

23 Sep 2025, 23:17

Type Values Removed Values Added
CPE cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
cpe:2.3:a:nvidia:nemo:*:*:*:*:*:*:*:*
CWE CWE-94
First Time Apple macos
Apple
Linux linux Kernel
Microsoft windows
Nvidia
Linux
Microsoft
Nvidia nemo
References () https://nvd.nist.gov/vuln/detail/CVE-2025-23304 - () https://nvd.nist.gov/vuln/detail/CVE-2025-23304 - US Government Resource
References () https://nvidia.custhelp.com/app/answers/detail/a_id/5686 - () https://nvidia.custhelp.com/app/answers/detail/a_id/5686 - Vendor Advisory
References () https://www.cve.org/CVERecord?id=CVE-2025-23304 - () https://www.cve.org/CVERecord?id=CVE-2025-23304 - Third Party Advisory

14 Aug 2025, 13:12

Type Values Removed Values Added
Summary
  • (es) La librería NVIDIA NeMo para todas las plataformas contiene una vulnerabilidad en el componente de carga de modelos, donde un atacante podría inyectar código manipulando archivos .nemo con metadatos maliciosos. Explotar esta vulnerabilidad podría provocar la ejecución remota de código y la manipulación de datos.

13 Aug 2025, 18:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-08-13 18:15

Updated : 2025-09-24 13:13


NVD link : CVE-2025-23304

Mitre link : CVE-2025-23304

CVE.ORG link : CVE-2025-23304


JSON object : View

Products Affected

microsoft

  • windows

nvidia

  • nemo

apple

  • macos

linux

  • linux_kernel
CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

CWE-94

Improper Control of Generation of Code ('Code Injection')