CVE-2025-23312: Code Injection
NVIDIA NeMo Framework for all platforms contains a vulnerability in the retrieval services component, where malicious data created by an attacker could cause a code injection. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, information disclosure, and data tampering.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-23312?
CVE-2025-23312 is classified as a high-severity vulnerability due to the potential for code execution and escalation of privileges.
How do I fix CVE-2025-23312?
To fix CVE-2025-23312, users should update to the latest version of the NVIDIA NeMo Framework as recommended by NVIDIA.
What does CVE-2025-23312 affect?
CVE-2025-23312 affects the retrieval services component of the NVIDIA NeMo Framework across all platforms.
What are the potential impacts of exploiting CVE-2025-23312?
Exploitation of CVE-2025-23312 could lead to code execution, privilege escalation, or information disclosure.
Who is impacted by CVE-2025-23312?
Any user or organization utilizing the NVIDIA NeMo Framework is potentially impacted by CVE-2025-23312.