Unrated severityNVD Advisory· Published Aug 13, 2025· Updated Feb 26, 2026
CVE-2025-23304
CVE-2025-23304
Description
NVIDIA NeMo library for all platforms contains a vulnerability in the model loading component, where an attacker could cause code injection by loading .nemo files with maliciously crafted metadata. A successful exploit of this vulnerability may lead to remote code execution and data tampering.
Affected products
2- NVIDIA/NVIDIA NeMo Frameworkv5Range: All versions prior to 2.3.2
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3News mentions
0No linked articles in our index yet.