Code Injection Vulnerability in NVIDIA Isaac-GR00T Python Component
CVE-2025-23296
7.8HIGH
What is CVE-2025-23296?
The NVIDIA Isaac-GR00T software, a robotics framework that utilizes Python, is susceptible to a code injection vulnerability. This issue arises when an attacker is able to manipulate a Python component within the platform, potentially leading to unauthorized code execution. Exploiting this vulnerability can result in escalation of privileges, allowing an attacker to gain heightened access to system resources, information disclosure, and compromise the integrity of data. It is crucial for users and organizations utilizing this framework to apply the necessary security patches and remain vigilant against potential exploits.
Affected Version(s)
NVIDIA Isaac-GR00T N1 All All versions that do not include code commit 9ca97e1