VYPR
Unrated severityNVD Advisory· Published Aug 13, 2025· Updated Feb 26, 2026

CVE-2025-23304

CVE-2025-23304

Description

NVIDIA NeMo library for all platforms contains a vulnerability in the model loading component, where an attacker could cause code injection by loading .nemo files with maliciously crafted metadata. A successful exploit of this vulnerability may lead to remote code execution and data tampering.

Affected products

2
  • Nvidia/Nemollm-fuzzy
  • NVIDIA/NVIDIA NeMo Frameworkv5
    Range: All versions prior to 2.3.2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

3

News mentions

0

No linked articles in our index yet.