Code Injection Vulnerability in NVIDIA Isaac-GR00T Python Component
CVE-2025-23296

7.8HIGH

Key Information:

Vendor

Nvidia

Vendor
CVE Published:
13 August 2025

What is CVE-2025-23296?

The NVIDIA Isaac-GR00T software, a robotics framework that utilizes Python, is susceptible to a code injection vulnerability. This issue arises when an attacker is able to manipulate a Python component within the platform, potentially leading to unauthorized code execution. Exploiting this vulnerability can result in escalation of privileges, allowing an attacker to gain heightened access to system resources, information disclosure, and compromise the integrity of data. It is crucial for users and organizations utilizing this framework to apply the necessary security patches and remain vigilant against potential exploits.

Affected Version(s)

NVIDIA Isaac-GR00T N1 All All versions that do not include code commit 9ca97e1

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-23296 : Code Injection Vulnerability in NVIDIA Isaac-GR00T Python Component