NVIDIA Megatron-LM Code Injection Vulnerability Allowing Arbitrary Code Execution

Vulnerability

A code injection vulnerability has been identified in NVIDIA Megatron-LM for all platforms. This issue arises in a script where an attacker can introduce malicious data, potentially leading to unauthorized code execution, escalation of privileges, information disclosure, and data tampering.

Impact

Exploitation of this vulnerability could result in arbitrary code execution, with elevated privileges, allowing an attacker to manipulate data or access sensitive information.

Added: Feb 3, 2026, 8:19 PM
Updated: Feb 3, 2026, 8:19 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
3.3
remediation
0.0
relevance
2.7
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.