Categories: Cyber Security News

Critical Flaws in NVIDIA NeMo AI Curator Allow System Takeover

NVIDIA has released a critical update for NVIDIA® NeMo Curator to address a high-severity code injection vulnerability.

Users are urged to download and install the latest Curator release from the NVIDIA NeMo GitHub repository and review detailed guidance on the NVIDIA Product Security portal.

Vulnerability Details

A newly disclosed vulnerability, tracked as CVE-2025-23307, affects all platforms supported by NVIDIA NeMo Curator.

An attacker who crafts a malicious file and tricks the Curator environment into processing it could achieve remote code execution, privilege escalation, unauthorized disclosure of sensitive information, or data tampering.

The vulnerability stems from insufficient validation of user-supplied inputs before dynamic code evaluation (CWE-94).

Under the CVSS v3.1 assessment, this flaw carries a base score of 7.8, reflecting its high impact and relatively low exploitation complexity (AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).

  • Attack Vector: Local file manipulation
  • Privileges Required: Low
  • User Interaction: None
  • Impact: High on confidentiality, integrity, and availability

NVIDIA’s risk assessment aggregates data from diverse deployments and may not fully represent the risk profile of every environment.

Administrators should evaluate the update’s urgency relative to their specific configurations and threat models.

Security Updates

To mitigate CVE-2025-23307, NVIDIA has published Curator version 25.07, which includes input sanitization and stricter evaluation controls.

All previous versions—across Windows, Linux, and macOS—are vulnerable. Users on older branch releases should upgrade to the latest branch to ensure continued protection.

CVE ID Affected Product Platform Affected Versions Updated Version
CVE-2025-23307 NVIDIA NeMo Curator Windows, Linux, macOS All versions prior to 25.07 25.07

Acknowledgements:

NVIDIA thanks D.K. for reporting CVE-2025-23307 and working with the NVIDIA Product Security Incident Response Team (PSIRT) to validate the fix.

Find this Story Interesting! Follow us on LinkedIn and X to Get More Instant Updates

The post Critical Flaws in NVIDIA NeMo AI Curator Allow System Takeover appeared first on Cyber Security News.

rssfeeds-admin

Recent Posts

New Alert: Hackers Hijack Corporate M365 Accounts with OAuth Device Codes

ANY.RUN, a leading provider of interactive malware analysis and threat intelligence solutions, has recently observed a surge…

29 minutes ago

Windows 11 25H2/24H2 Update Fixes Bluetooth Visibility Problems

Microsoft has released an out-of-band hotpatch, KB5084897, addressing a critical Bluetooth device visibility issue impacting…

29 minutes ago

Microsoft Introduces AI-Powered Troubleshooting for Purview Data Lifecycle Management

Microsoft has announced the release of an AI-powered troubleshooting capability for Microsoft Purview Data Lifecycle…

29 minutes ago

Illinois residents could soon use ‘plug in’ solar panels without extra fees or approval

Illinois Senate Bill 3104 aims to make it easier for residents, including renters and condominium…

40 minutes ago

Dune: Part 3 Trailer Showcases the Epic Conclusion of Denis Villeneuve’s Trilogy and a First-Look at Robert Pattinson’s Villain

The first trailer for Dune: Part 3 has arrived, and it gives us our best…

43 minutes ago

Hulu Renews Hit Drama Paradise For Its Third Season Ahead of Season 2 Finale

Hulu’s hit new show Paradise has officially been renewed for its third season, just under…

43 minutes ago

This website uses cookies.