NVIDIA Megatron-LM Code Injection Vulnerability in NQ Component Allowing Code Execution and Privilege Escalation

Vulnerability

A code injection vulnerability has been identified in NVIDIA Megatron-LM for all platforms, specifically within the tasks/orqa/unsupervised/nq.py component. This vulnerability allows an attacker to inject malicious code, which could be executed, potentially leading to unauthorized code execution, escalation of privileges, information disclosure, and data tampering.

Impact

Exploitation of this vulnerability could result in unauthorized code execution, elevated privileges, disclosure of sensitive information, and unauthorized modification of data.

Remediation

Users are advised to update to version 0.13.1 or 0.12.3 and later. The updated versions are available on the NVIDIA Megatron-LM GitHub releases page.

Added: Sep 24, 2025, 2:20 PM
Updated: Sep 24, 2025, 9:39 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
7.5
exploitability
5.2
remediation
7.7
relevance
0.6
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.