Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2025-23304


NVIDIA NeMo library for all platforms contains a vulnerability in the model loading component, where an attacker could cause code injection by loading .nemo files with maliciously crafted metadata. A successful exploit of this vulnerability may lead to remote code execution and data tampering.


Published

2025-08-13T18:15:29.920

Last Modified

2025-09-24T13:13:00.823

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 7.8 (HIGH)

Weaknesses
  • Type: Secondary
    CWE-22
  • Type: Primary
    CWE-94

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application nvidia nemo < 2.3.2 Yes
Operating System apple macos - No
Operating System linux linux_kernel - No
Operating System microsoft windows - No

References