Intel

AIKIDO-2025-10585

nemo-toolkit is vulnerable to Unsafe Deserialization

Unsafe DeserializationCVE-2025-23303 Published Aug 25, 2025

85

High Risk

This Affects:

PYTHONnemo-toolkit
0.0.1 - 2.3.1
Fixed in 2.3.2
Are you affected? Scan for Free

TL;DR

Affected versions of this package are vulnerable to deserialization of untrusted data. Specially crafted input can be deserialized without proper validation, allowing attackers to execute arbitrary code or manipulate application data.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

nemo-toolkit is vulnerable to Unsafe Deserialization in versions 0.0.1 - 2.3.1.

How to fix this

Upgrade the nemo-toolkit library to the patch version.