CVE-2025-23304

NVIDIA NeMo library for all platforms contains a vulnerability in the model loading component, where an attacker could cause code injection by loading .nemo files with maliciously crafted metadata. A successful exploit of this vulnerability may lead to remote code execution and data tampering.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:a:nvidia:nemo:*:*:*:*:*:*:*:*
OR cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*

History

23 Sep 2025, 23:17

Type Values Removed Values Added
CWE CWE-94
References () https://nvd.nist.gov/vuln/detail/CVE-2025-23304 - () https://nvd.nist.gov/vuln/detail/CVE-2025-23304 - US Government Resource
References () https://nvidia.custhelp.com/app/answers/detail/a_id/5686 - () https://nvidia.custhelp.com/app/answers/detail/a_id/5686 - Vendor Advisory
References () https://www.cve.org/CVERecord?id=CVE-2025-23304 - () https://www.cve.org/CVERecord?id=CVE-2025-23304 - Third Party Advisory
CPE cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:*
cpe:2.3:a:nvidia:nemo:*:*:*:*:*:*:*:*
First Time Nvidia
Nvidia nemo
Linux
Microsoft windows
Linux linux Kernel
Microsoft
Apple
Apple macos

14 Aug 2025, 13:12

Type Values Removed Values Added
Summary
  • (es) La librería NVIDIA NeMo para todas las plataformas contiene una vulnerabilidad en el componente de carga de modelos, donde un atacante podría inyectar código manipulando archivos .nemo con metadatos maliciosos. Explotar esta vulnerabilidad podría provocar la ejecución remota de código y la manipulación de datos.

13 Aug 2025, 18:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-08-13 18:15

Updated : 2025-09-24 13:13


NVD link : CVE-2025-23304

Mitre link : CVE-2025-23304

CVE.ORG link : CVE-2025-23304


JSON object : View

Products Affected

microsoft

  • windows

linux

  • linux_kernel

apple

  • macos

nvidia

  • nemo
CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

CWE-94

Improper Control of Generation of Code ('Code Injection')