VYPR
Unrated severityNVD Advisory· Published Sep 24, 2025· Updated Sep 24, 2025

CVE-2025-23354

CVE-2025-23354

Description

NVIDIA Megatron-LM for all platforms contains a vulnerability in the ensemble_classifer script where malicious data created by an attacker may cause an injection. A successful exploit of this vulnerability may lead to code execution, escalation of privileges, Information disclosure, and data tampering.

Affected products

2
  • NVIDIA/Megatron-LMv5
    Range: All versions prior to 0.13.1 and 0.12.3

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

3

News mentions

0

No linked articles in our index yet.