CVE-2025-23250

CWE-22Path Traversal3 documents3 sources
Severity
9.8CRITICAL
EPSS
0.4%
top 38.84%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 22

Description

NVIDIA NeMo Framework contains a vulnerability where an attacker could cause an improper limitation of a pathname to a restricted directory by an arbitrary file write. A successful exploit of this vulnerability might lead to code execution and data tampering.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:H/A:LExploitability: 2.8 | Impact: 4.7

Affected Packages2 packages

CVEListV5nvidia/nemo_frameworkAll versions prior to 25.02
NVDnvidia/nemo< 25.02

🔴Vulnerability Details

2
GHSA
GHSA-gxj5-h4j6-fmfx: NVIDIA NeMo Framework contains a vulnerability where an attacker could cause an improper limitation of a pathname to a restricted directory by an arbi2025-04-22
CVEList
CVE-2025-23250: NVIDIA NeMo Framework contains a vulnerability where an attacker could cause an improper limitation of a pathname to a restricted directory by an arbi2025-04-22
CVE-2025-23250 (CRITICAL CVSS 9.8) | NVIDIA NeMo Framework contains a vu | cvebase.io