CVE-2025-23349

7.8

NVIDIA · Megatron-LM

NVIDIA Megatron-LM contains a code injection vulnerability in the nq.py component, which can lead to remote code execution, privilege escalation, and data compromise.

Executive summary

A critical code injection vulnerability in NVIDIA Megatron-LM allows local authenticated attackers to execute arbitrary code and compromise system integrity.

Vulnerability

The vulnerability exists in the tasks/orqa/unsupervised/nq.py component due to improper control of code generation (CWE-94). An attacker with local low-level privileges can inject malicious code, leading to full system compromise.

Business impact

The potential for unauthorized code execution poses a severe risk to organizational data and system availability. With a CVSS score of 7.8, this high-severity flaw enables attackers to escalate privileges and tamper with sensitive information, potentially leading to significant operational disruption and data loss.

Remediation

Immediate Action: Update NVIDIA Megatron-LM to version 0.13.1 or 0.12.3 immediately to remediate the vulnerable code injection flaw.

Proactive Monitoring: Review system access logs for unauthorized attempts to modify or execute scripts within the Megatron-LM directory structure.

Compensating Controls: Restrict local system access to authorized personnel and implement strict file integrity monitoring on the deployment directory to detect unauthorized code changes.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Given the potential for code execution and privilege escalation, organizations using NVIDIA Megatron-LM must prioritize this update. Administrators should verify their current version against the patched releases of 0.13.1 or 0.12.3 and deploy the updates immediately to mitigate the risk of exploitation.

More NVIDIA CVEs

Sources