CVE-2025-23315
7.8NVIDIA · NeMo Framework
NVIDIA NeMo Framework contains a code injection vulnerability in its export and deploy component that may lead to arbitrary code execution, privilege escalation, and data tampering.
Executive summary
A critical code injection vulnerability in the NVIDIA NeMo Framework allows local attackers to execute arbitrary code and compromise system integrity.
Vulnerability
This vulnerability is a code injection flaw (CWE-94) within the export and deploy component of the framework. According to the CVSS vector (AV:L/PR:L/UI:N), it requires a local attacker with low-level privileges to supply malicious data to the vulnerable component.
Business impact
Successful exploitation of this flaw poses a severe risk to organizational infrastructure, as it enables an attacker to achieve remote code execution and escalate privileges. This could lead to full system compromise, unauthorized data access, and potential tampering with sensitive machine learning models or deployment pipelines. Given the CVSS score of 7.8, this vulnerability represents a high-severity risk that requires immediate attention to prevent unauthorized system control.
Remediation
Immediate Action: Update the NVIDIA NeMo Framework to version 2.4.0 or later as specified in the vendor security advisory.
Proactive Monitoring: Review system and application logs for unusual process execution patterns or unauthorized attempts to access the export and deploy components.
Compensating Controls: Restrict local access to the systems running the NeMo Framework to only authorized users, and implement host-based intrusion detection systems to monitor for unexpected code execution.
Exploitation status
Public Exploit Available: No
Analyst recommendation
The high severity of this vulnerability, combined with the potential for full system compromise, necessitates prompt remediation. Organizations utilizing the NVIDIA NeMo Framework should prioritize upgrading to version 2.4.0 immediately to mitigate the risk of code injection and associated security impacts.