CVE-2025-23296
7.8NVIDIA · Isaac-GR00T
NVIDIA Isaac-GR00T contains a code injection vulnerability in a Python component that may lead to arbitrary code execution, privilege escalation, and data tampering.
Executive summary
A critical code injection vulnerability in NVIDIA Isaac-GR00T poses a significant risk of arbitrary code execution and system compromise for local users.
Vulnerability
This is a code injection vulnerability (CWE-94) residing in a Python component of the software. Based on the CVSS vector (PR:L), the vulnerability requires a local authenticated user to trigger the flaw, which can then be leveraged to achieve full system compromise.
Business impact
Successful exploitation allows an attacker to execute arbitrary code, escalate privileges, and manipulate sensitive data within the environment. With a CVSS score of 7.8, this represents a high-severity risk that could lead to unauthorized control over the host system and potential lateral movement, resulting in significant operational and security impacts.
Remediation
Immediate Action: Update the NVIDIA Isaac-GR00T environment to a version that incorporates code commit 9ca97e1 or newer as specified in the vendor security bulletin.
Proactive Monitoring: Monitor system logs for unusual process execution patterns or unexpected modifications to configuration files associated with the Isaac-GR00T Python environment.
Compensating Controls: Restrict local system access to authorized personnel only to limit the pool of potential attackers who could exploit this local-access vulnerability.
Exploitation status
Public Exploit Available: No (exploit_available: false)
Analyst recommendation
Given the potential for complete system compromise and privilege escalation, organizations utilizing NVIDIA Isaac-GR00T should prioritize applying the vendor-provided patch. Administrators must verify that the environment is updated to include the remediating code commit to ensure the injection vector is effectively closed.