CVE-2025-23303: Critical severity Nvidia NeMo framework vulnerability
Published Aug 13, 2025
·Updated
NVIDIA NeMo Framework for all platforms contains a vulnerability where a user could cause a deserialization of untrusted data by remote code execution. A successful exploit of this vulnerability might lead to code execution and data tampering.
Affected Software
5 affected components
Nvidia NeMo framework
All of the following
Nvidia NeMo<2.3.2
Any of the following
Apple macOS
Linux Linux kernel
Microsoft Windows
Event History
Aug 13, 2025
CVE Published
via MITRE·05:15 PM
Data Sourced
via MITRE·05:15 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·06:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-23303?
CVE-2025-23303 is considered a critical vulnerability due to its potential for remote code execution.
2
How do I fix CVE-2025-23303?
To fix CVE-2025-23303, update the NVIDIA NeMo Framework to the latest version that addresses this vulnerability.
3
What type of vulnerability is CVE-2025-23303?
CVE-2025-23303 is a deserialization vulnerability that can lead to remote code execution.
4
Who is affected by CVE-2025-23303?
CVE-2025-23303 affects users of the NVIDIA NeMo Framework across all platforms.
5
What are the potential impacts of exploiting CVE-2025-23303?
Exploitation of CVE-2025-23303 may lead to unauthorized code execution and data tampering.