CVE-2025-23349

NVIDIA Megatron-LM for all platforms contains a vulnerability in the tasks/orqa/unsupervised/nq.py component, where an attacker may cause a code injection. A successful exploit of this vulnerability may lead to code execution, escalation of privileges, information disclosure, and data tampering.
Code Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.8 HIGH
LOCAL
LOW
LOW
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvidiaCNA
7.8 HIGH
LOCAL
LOW
LOW
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CISA-ADPADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 5%
VendorProductVersion
nvidiamegatron-lm
𝑥
< 0.12.3
nvidiamegatron-lm
0.13.0
nvidiamegatron-lm
0.13.0:rc0
nvidiamegatron-lm
0.13.0:rc1
nvidiamegatron-lm
0.13.0:rc2
nvidiamegatron-lm
0.13.0:rc3
nvidiamegatron-lm
0.13.0:rc4
𝑥
= Vulnerable software versions