CVE-2025-23304

NVIDIA NeMo library for all platforms contains a vulnerability in the model loading component, where an attacker could cause code injection by loading .nemo files with maliciously crafted metadata. A successful exploit of this vulnerability may lead to remote code execution and data tampering.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:a:nvidia:nemo:*:*:*:*:*:*:*:*
OR cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*

History

23 Sep 2025, 23:17

Type Values Removed Values Added
First Time Nvidia
Apple
Linux
Nvidia nemo
Microsoft
Microsoft windows
Apple macos
Linux linux Kernel
References () https://nvd.nist.gov/vuln/detail/CVE-2025-23304 - () https://nvd.nist.gov/vuln/detail/CVE-2025-23304 - US Government Resource
References () https://nvidia.custhelp.com/app/answers/detail/a_id/5686 - () https://nvidia.custhelp.com/app/answers/detail/a_id/5686 - Vendor Advisory
References () https://www.cve.org/CVERecord?id=CVE-2025-23304 - () https://www.cve.org/CVERecord?id=CVE-2025-23304 - Third Party Advisory
CPE cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:*
cpe:2.3:a:nvidia:nemo:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
CWE CWE-94

14 Aug 2025, 13:12

Type Values Removed Values Added
Summary
  • (es) La librería NVIDIA NeMo para todas las plataformas contiene una vulnerabilidad en el componente de carga de modelos, donde un atacante podría inyectar código manipulando archivos .nemo con metadatos maliciosos. Explotar esta vulnerabilidad podría provocar la ejecución remota de código y la manipulación de datos.

13 Aug 2025, 18:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-08-13 18:15

Updated : 2025-09-24 13:13


NVD link : CVE-2025-23304

Mitre link : CVE-2025-23304

CVE.ORG link : CVE-2025-23304


JSON object : View

Products Affected

apple

  • macos

microsoft

  • windows

nvidia

  • nemo

linux

  • linux_kernel
CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

CWE-94

Improper Control of Generation of Code ('Code Injection')