CVE-2025-23354
NVIDIA Megatron-LM for all platforms contains a vulnerability in the ensemble_classifer script where malicious data created by an attacker may cause an injection. A successful exploit of this vulnerability may lead to code execution, escalation of privileges, Information disclosure, and data tampering.
Package Versions Affected
Automatically patch vulnerabilities without upgrading
CVSS Version



Related Resources
References
https://nvidia.custhelp.com/app/answers/detail/a_id/5698, https://nvd.nist.gov/vuln/detail/CVE-2025-23354, https://www.cve.org/CVERecord?id=CVE-2025-23354
