CVE-2025-23306
NVIDIA Megatron-LM for all platforms contains a vulnerability in the megatron/training/
arguments.py component where an attacker could cause a code injection issue by providing a malicious input. A successful exploit of this vulnerability may lead to code execution, escalation of privileges, information disclosure, and data tampering.
Package Versions Affected
Automatically patch vulnerabilities without upgrading
CVSS Version



Related Resources
References
https://nvidia.custhelp.com/app/answers/detail/a_id/5685, https://nvd.nist.gov/vuln/detail/CVE-2025-23306, https://www.cve.org/CVERecord?id=CVE-2025-23306
