CVE-2025-23249

CVSS 3.1 Score 7.6 of 10 (high)

Details

Published Apr 22, 2025
Updated: Apr 23, 2025
CWE ID 502

Summary

CVE-2025-23249 is a deserialization vulnerability affecting NVIDIA NeMo Framework. This issue enables a remote user to execute arbitrary code, potentially leading to serious consequences such as code execution and data tampering. The vulnerability arises due to insufficient input validation in the framework's deserialization process. Users are urged to apply the necessary patches to mitigate this risk and protect their systems.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share