NVIDIA Megatron-LM Code Injection Vulnerability Leading to Code Execution and Privilege Escalation

Vulnerability

A code injection vulnerability has been identified in NVIDIA Megatron-LM for all platforms. This issue arises in a Python component, where an attacker can exploit the vulnerability by providing a malicious file. Successful exploitation may result in unauthorized code execution, elevated privileges, information disclosure, and data tampering.

Impact

Exploitation of this vulnerability allows for arbitrary code execution, unauthorized privilege escalation, and could lead to disclosure of sensitive information and unauthorized modification of data.

Remediation

Users are advised to update to version 0.12.1 or later. The update is available on the NVIDIA Megatron-LM GitHub Releases page.

Added: Jun 24, 2025, 4:28 PM
Updated: Jun 24, 2025, 4:28 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
7.5
exploitability
6.4
remediation
7.7
relevance
0.2
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.