- Description
- NVIDIA Megatron-LM for all platforms contains a vulnerability in a python component where an attacker may cause a code injection issue by providing a malicious file. A successful exploit of this vulnerability may lead to Code Execution, Escalation of Privileges, Information Disclosure and Data Tampering.
- Source
- psirt@nvidia.com
- NVD status
- Awaiting Analysis
CVSS 3.1
- Type
- Secondary
- Base score
- 7.8
- Impact score
- 5.9
- Exploitability score
- 1.8
- Vector string
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- Severity
- HIGH
- psirt@nvidia.com
- CWE-94
- Hype score
- Not currently trending
NVIDIA's Megatron-LM framework has critical vulnerabilities (#CVE-2025-23264, #CVE-2025-23265) allowing remote code execution via insecure input handling. Organizations using versions before 0.12.0 must update immediately to prevent breaches. ⚠️ #DataBre… https://t.co/zrJVm
@TweetThreatNews
25 Jun 2025
52 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🚨 NVIDIA corrige dos vulnerabilidades críticas en su framework de IA Megatron-LM (CVE-2025-23264 y 23265). 🔧 Permiten ejecutar código malicioso y escalar privilegios con solo un archivo manipulado. 📌 Si usas IA en producción, actualiza ya a la versión 0.12.1.
@gorkaelbochi
25 Jun 2025
2 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CVE-2025-23264 Code Injection Vulnerability in NVIDIA Megatron-LM Python Component https://t.co/dHCSxfjjhK
@VulmonFeeds
24 Jun 2025
22 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CVE-2025-23264 NVIDIA Megatron-LM for all platforms contains a vulnerability in a python component where an attacker may cause a code injection issue by providing a malicious file. … https://t.co/uNqWKr1E7G
@CVEnew
24 Jun 2025
421 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes