NVIDIA Megatron-LM Code Injection Vulnerability Allowing Arbitrary Code Execution and Privilege Escalation

Vulnerability

A code injection vulnerability has been identified in NVIDIA Megatron-LM, all platforms, specifically within the megatron/training/arguments.py component. This vulnerability allows an attacker to inject malicious input, potentially leading to arbitrary code execution, escalation of privileges, unauthorized information disclosure, and data tampering.

Impact

Exploitation of this vulnerability could result in arbitrary code execution, unauthorized privilege escalation, information disclosure, and unauthorized data modification.

Remediation

Users are advised to update to version 0.12.2 or later. Instructions for downloading the latest version are available on the NVIDIA Megatron-LM GitHub Releases page.

Added: Aug 13, 2025, 9:39 PM
Updated: Aug 13, 2025, 9:39 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
10.0
exploitability
5.2
remediation
7.7
relevance
0.4
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.