CVE-2025-23307
7.8NVIDIA · NeMo Curator
NVIDIA NeMo Curator contains a code injection vulnerability triggered by malicious files that may lead to code execution, privilege escalation, information disclosure, and data tampering.
Executive summary
A code injection vulnerability in NVIDIA NeMo Curator allows authenticated local attackers to execute arbitrary code and compromise system integrity.
Vulnerability
This vulnerability is a code injection flaw (CWE-94) that occurs when the application improperly processes malicious files. Based on the CVSS vector (PR:L), this requires a local user with low privileges to trigger the execution.
Business impact
Successful exploitation of this flaw poses a severe risk to organizational data and system availability. With a CVSS score of 7.8, the vulnerability permits full system impact, including unauthorized data access, modification, and potential lateral movement within the environment.
Remediation
Immediate Action: Update NVIDIA NeMo Curator to version 25.07 or later as mandated by the vendor security advisory.
Proactive Monitoring: Review system and application logs for unexpected file handling activities or unauthorized process execution associated with the NeMo Curator environment.
Compensating Controls: Restrict file system permissions to ensure that only authorized users can place files in directories processed by NeMo Curator, thereby limiting the potential attack surface.
Exploitation status
Public Exploit Available: Unknown.
Analyst recommendation
Given the potential for code execution and privilege escalation, this vulnerability must be treated with high priority. IT administrators should verify their current version of NeMo Curator and apply the 25.07 update immediately to prevent potential exploitation.