NVIDIA NeMo Framework: crafted data in the NLP component injects code into the running job (CWE-94)
Impact
Attacker-controlled data processed by the NeMo NLP component executes arbitrary code inside the training or inference job, which typically holds a GPU, a service account and mounted object-storage credentials; NVIDIA split this NLP-component code-injection issue across 2 ids (CVE-2025-23313, CVE-2025-23314) in bulletin 5689 without describing any difference between them.
Who can reach it
Requires the job to load an attacker-influenced artifact - a checkpoint, .nemo file, config, tokenizer or dataset. Any pipeline that pulls from a public model hub, a customer bucket, or a tenant-supplied path is in scope.
What to do
Upgrade NeMo Framework to 2.4.0 (GitHub or PyPI) and rebuild every training/inference image that embeds it - one bump clears both ids. Cost: image rebuild and job restart; no host driver or firmware change. The durable control is refusing to deserialize untrusted checkpoints at all: prefer safetensors-style formats and treat pickle-bearing artifacts as executable code.
Also covers 1 CVE
The vendor assigned a separate id to each affected code path. They share this advisory, this score and this fix, so they are one entry here.
References
Related entries
- NVIDIA NeMo Framework: Crafted data in the export-and-deploy component injects codeCVE-2025-23315 · NVIDIA NeMo FrameworkHigh
- NVIDIA NeMo Framework: Malicious input causes improper control of code generation, reaching code executionCVE-2025-23361 · NVIDIA NeMo FrameworkHigh
- NVIDIA NeMo Framework: Crafted data in the BERT services component injects codeCVE-2025-33178 · NVIDIA NeMo FrameworkHigh
- NVIDIA NeMo Framework: Crafted data in the NLP and LLM components injects codeCVE-2025-33204 · NVIDIA NeMo FrameworkHigh
- NVIDIA NeMo Framework: Crafted data reaches code injection and privilege escalation in the job contextCVE-2025-33226 · NVIDIA NeMo FrameworkHigh
- NVIDIA NeMo Framework: OS command injection reaches code execution with the job's privilegesCVE-2026-24252 · NVIDIA NeMo FrameworkHigh
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.