Vulnerability Description
NVIDIA Megatron-LM for all platforms contains a vulnerability in a python component where an attacker may cause a code injection issue by providing a malicious file. A successful exploit of this vulnerability may lead to Code Execution, Escalation of Privileges, Information Disclosure and Data Tampering.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Nvidia | Megatron-Lm | < 0.12.1 |
Related Weaknesses (CWE)
References
- https://nvidia.custhelp.com/app/answers/detail/a_id/5663Vendor Advisory
FAQ
What is CVE-2025-23265?
CVE-2025-23265 is a vulnerability with a CVSS score of 7.8 (HIGH). NVIDIA Megatron-LM for all platforms contains a vulnerability in a python component where an attacker may cause a code injection issue by providing a malicious file. A successful exploit of this vulne...
How severe is CVE-2025-23265?
CVE-2025-23265 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-23265?
Check the references section above for vendor advisories and patch information. Affected products include: Nvidia Megatron-Lm.