Description
NVIDIA NeMo Framework for all platforms contains a vulnerability where a user could cause a deserialization of untrusted data by remote code execution. A successful exploit of this vulnerability might lead to code execution and data tampering.
Problem types
CWE-502 Deserialization of Untrusted Data
Product status
All versions prior to 2.3.2
References
nvd.nist.gov/vuln/detail/CVE-2025-23303
www.cve.org/CVERecord?id=CVE-2025-23303
nvidia.custhelp.com/app/answers/detail/a_id/5686