CVE-2025-23313: Code Injection
NVIDIA NeMo Framework for all platforms contains a vulnerability in the NLP component, where malicious data created by an attacker could cause a code injection issue. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, information disclosure, and data tampering.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-23313?
The severity of CVE-2025-23313 is categorized as high due to potential code execution and privilege escalation risks.
How do I fix CVE-2025-23313?
To fix CVE-2025-23313, update to the latest version of the NVIDIA NeMo Framework where the vulnerability is patched.
What attack vectors are associated with CVE-2025-23313?
CVE-2025-23313 can be exploited through malicious data inputs that trigger a code injection issue.
What are the consequences of exploiting CVE-2025-23313?
Exploiting CVE-2025-23313 may lead to code execution, privilege escalation, information disclosure, and data manipulation.
Who is affected by CVE-2025-23313?
CVE-2025-23313 affects all platforms that utilize the NVIDIA NeMo Framework for natural language processing.