First published: Thu May 01 2025(Updated: )
NVIDIA TensorRT-LLM for any platform contains a vulnerability in python executor where an attacker may cause a data validation issue by local access to the TRTLLM server. A successful exploit of this vulnerability may lead to code execution, information disclosure and data tampering.
Credit: psirt@nvidia.com
Affected Software | Affected Version | How to fix |
---|---|---|
NVIDIA TensorRT-LLM | ||
NVIDIA vGPU software |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-23245 is considered to have a high severity due to the potential for code execution and data tampering.
To fix CVE-2025-23245, update to the latest version of NVIDIA TensorRT-LLM as recommended by NVIDIA.
CVE-2025-23245 affects the NVIDIA TensorRT-LLM on any platform where it is deployed.
CVE-2025-23245 can facilitate attacks that lead to code execution, information disclosure, and data tampering.
Any user with local access to the TRTLLM server could be vulnerable to the exploitation of CVE-2025-23245.