« Back to list

CVE-2025-23307

Status: AnalyzedHigh (7.8)—

NVIDIA NeMo Curator for all platforms contains a vulnerability where a malicious file created by an attacker could allow code injection. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, information disclosure, and data tampering.

CVSS

Exploitation probability (EPSS)

EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).

🎯 ATT&CK techniques

How this vulnerability is exploited and what the attacker gains, in MITRE ATT&CK terms.

AV:L + PR:L indica escalada local; CWE-94 (code injection) + descripción «code execution» y «escalation of privileges» confirma T1059 como impacto primario y T1068 como secundario tras escalar.

Inferred by our analysis agent from the official description, CVSS vector and CWE, and checked by a supervisor. May contain errors.

🛡️ ATT&CK mitigations that cover these techniques

Affected technologies (1)

CWEs

References

Raw JSON (NVD)

Show
{
  "id": "CVE-2025-23307",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2025-23307",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "total"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2025-08-27T03:55:16.733752Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "psirt@nvidia.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.8,
          "attackVector": "LOCAL",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 1.8
      }
    ]
  },
  "affected": [
    {
      "source": "psirt@nvidia.com",
      "affectedData": [
        {
          "vendor": "NVIDIA",
          "product": "NVIDIA NeMo Curator",
          "versions": [
            {
              "status": "affected",
              "version": "All versions prior to Curator 25.07"
            }
          ],
          "platforms": [
            "Windows",
            "Linux",
            "macOS"
          ],
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2025-08-26T19:15:38.397",
  "references": [
    {
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-23307",
      "tags": [
        "Technical Description"
      ],
      "source": "psirt@nvidia.com"
    },
    {
      "url": "https://nvidia.custhelp.com/app/answers/detail/a_id/5690",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "psirt@nvidia.com"
    },
    {
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-23307",
      "tags": [
        "Technical Description"
      ],
      "source": "psirt@nvidia.com"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "psirt@nvidia.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-94"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "NVIDIA NeMo Curator for all platforms contains a vulnerability where a malicious file created by an attacker could allow code injection. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, information disclosure, and data tampering."
    },
    {
      "lang": "es",
      "value": "NVIDIA NeMo Curator para todas las plataformas contiene una vulnerabilidad que permite la inyección de código mediante un archivo malicioso creado por un atacante. Una explotación exitosa de esta vulnerabilidad podría provocar la ejecución de código, la escalada de privilegios, la divulgación de información y la manipulación de datos."
    }
  ],
  "lastModified": "2026-06-17T08:53:22.883",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:nvidia:nemo_curator:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "4A779C9D-0345-44B3-BEDA-EA8BA3E54F4B",
              "versionEndExcluding": "25.07"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "psirt@nvidia.com"
}