CVE-2025-23313
7.8NVIDIA · NeMo Framework
NVIDIA NeMo Framework contains a code injection vulnerability in the NLP component, allowing an attacker to trigger arbitrary code execution, privilege escalation, or data tampering.
Executive summary
A critical code injection vulnerability in the NVIDIA NeMo Framework allows local attackers to achieve full system compromise, including privilege escalation and data manipulation.
Vulnerability
The vulnerability exists within the NLP component of the NeMo Framework due to improper control of generated code (CWE-94). An attacker with low-level local privileges can supply malicious input to trigger code injection, resulting in full system impact.
Business impact
Successful exploitation of this flaw poses a severe risk to organizational data integrity and system availability. Because the vulnerability allows for code execution and privilege escalation, an attacker could gain complete control over the affected infrastructure, leading to unauthorized access to sensitive NLP models, data exfiltration, or total system disruption. The CVSS score of 7.8 reflects the high severity of these potential outcomes.
Remediation
Immediate Action: Update the NVIDIA NeMo Framework to version 2.4.0 or later immediately to incorporate the required security patches.
Proactive Monitoring: Monitor system logs for unauthorized process execution, unusual privilege escalation attempts, or unexpected input patterns directed at NLP processing modules.
Compensating Controls: Restrict access to the host environment where the NeMo Framework is deployed, ensuring that only trusted users have the local access required to interface with the vulnerable NLP components.
Exploitation status
Public Exploit Available: No.
Analyst recommendation
Given the potential for complete system compromise and privilege escalation, this vulnerability must be treated as a high priority for remediation. Administrators should verify the current version of the NeMo Framework in their environment and deploy version 2.4.0 without delay to mitigate the risk of code injection attacks.