NVIDIA Megatron LM Flaw Allows Attackers to Inject Malicious Code

NVIDIA Megatron LM Flaw Allows Attackers to Inject Malicious Code

NVIDIA has released a security update for its Megatron-LM framework after discovering two critical vulnerabilities that could lead to remote code execution and data breaches. Organizations using versions prior to 0.12.0 are urged to update immediately to prevent potential exploitation. #CVE-2025-23264 #CVE-2025-23265 #MegatronLM

Keypoints

  • NVIDIA issued an urgent security update for its Megatron-LM framework due to critical vulnerabilities.
  • The flaws allow attackers to inject malicious code through insecure input handling in the Python component.
  • Both vulnerabilities have a high severity score of 7.8 on CVSS v3.1, with no user interaction required for exploits.
  • Successfully exploiting these flaws can lead to remote code execution, privilege escalation, and data tampering.
  • Users are advised to update to version 0.12.1 immediately to protect their AI models and sensitive data.

Read More: https://gbhackers.com/nvidia-megatron-lm-flaw/