CVE-2025-23251: Code Injection
Published Apr 22, 2025
·Updated
NVIDIA NeMo Framework contains a vulnerability where a user could cause an improper control of generation of code by remote code execution. A successful exploit of this vulnerability might lead to code execution and data tampering.
Affected Software
5 affected components
Nvidia NeMo framework
All of the following
Nvidia NeMo<25.02
Any of the following
Apple macOS
Linux Linux kernel
Microsoft Windows
Event History
Apr 22, 2025
CVE Published
via MITRE·03:42 PM
Data Sourced
via MITRE·03:42 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·04:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-23251?
CVE-2025-23251 has a high severity rating due to the potential for remote code execution.
2
How do I fix CVE-2025-23251?
To fix CVE-2025-23251, update your NVIDIA NeMo Framework to the latest patched version provided by NVIDIA.
3
What type of vulnerability is CVE-2025-23251?
CVE-2025-23251 is categorized as a remote code execution vulnerability affecting the NVIDIA NeMo Framework.
4
Who is affected by CVE-2025-23251?
Users of NVIDIA NeMo Framework are vulnerable to CVE-2025-23251 if they have not applied the necessary updates.
5
What could be the impact of exploiting CVE-2025-23251?
Exploiting CVE-2025-23251 could lead to unauthorized code execution and potential data tampering.