CVE-2025-23349
NVIDIA Megatron-LM for all platforms contains a vulnerability in the tasks/orqa/unsupervised/nq.py component, where an attacker may cause a code injection. A successful exploit of this vulnerability may lead to code execution, escalation of privileges, information disclosure, and data tampering.
Package Versions Affected
Automatically patch vulnerabilities without upgrading
CVSS Version



Related Resources
References
https://nvidia.custhelp.com/app/answers/detail/a_id/5698, https://nvd.nist.gov/vuln/detail/CVE-2025-23349, https://www.cve.org/CVERecord?id=CVE-2025-23349
