VYPR
High severity7.8NVD Advisory· Published Aug 13, 2025· Updated Jun 17, 2026

CVE-2025-23306

CVE-2025-23306

Description

NVIDIA Megatron-LM for all platforms contains a vulnerability in the megatron/training/ arguments.py component where an attacker could cause a code injection issue by providing a malicious input. A successful exploit of this vulnerability may lead to code execution, escalation of privileges, information disclosure, and data tampering.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • cpe:2.3:a:nvidia:megatron-lm:*:*:*:*:*:*:*:*+ 2 more
    • cpe:2.3:a:nvidia:megatron-lm:*:*:*:*:*:*:*:*range: <0.12.2
    • (no CPE)
    • (no CPE)range: All versions prior to 0.12.2

Patches

Vulnerability mechanics

References

3

News mentions

0

No linked articles in our index yet.