← Vulnerability feed

Vulnerability record · CVE-2025-23353 · published 24 September 2025

CVE-2025-23353: Nvidia megatron-lm code injection vulnerability

Nvidia · Megatron Lm

NVIDIA Megatron-LM for all platforms contains a vulnerability in the msdp preprocessing script where malicious data created by an attacker may cause an injection. A successful exploit of this vulnerability may lead to code execution, escalation of privileges, Information disclosure, and data tampering.

7.8 CVSS 3.1 High EPSS 0.24% · top 86.7% CWE-94 · Code injection
7.8CVSS 3.1 base score
0.24%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
3References
17 Jun 2026Last modified by NVD

Description

NVIDIA Megatron-LM for all platforms contains a vulnerability in the msdp preprocessing script where malicious data created by an attacker may cause an injection. A successful exploit of this vulnerability may lead to code execution, escalation of privileges, Information disclosure, and data tampering.

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2025-23353 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.8CVE-2026-24150Nvidia megatron-lm deserialization of untrusted data vulnerabilityNVIDIA Megatron-LM contains a vulnerability in checkpoint loading where an Attacker may cause an RCE by convincing a user to load a maliciously craft…EPSS 0.21%7.8CVE-2026-24151Nvidia megatron-lm deserialization of untrusted data vulnerabilityNVIDIA Megatron-LM contains a vulnerability in inferencing where an Attacker may cause an RCE by convincing a user to load a maliciously crafted inpu…EPSS 0.21%7.8CVE-2026-24152Nvidia megatron-lm deserialization of untrusted data vulnerabilityNVIDIA Megatron-LM contains a vulnerability in checkpoint loading where an Attacker may cause an RCE by convincing a user to load a maliciously craft…EPSS 0.21%7.8CVE-2025-33247Nvidia megatron-lm deserialization of untrusted data vulnerabilityNVIDIA Megatron LM contains a vulnerability in quantization configuration loading, which could allow remote code execution. A successful exploit of t…EPSS 0.32%7.8CVE-2025-33248Nvidia megatron-lm deserialization of untrusted data vulnerabilityNVIDIA Megatron-LM contains a vulnerability in the hybrid conversion script where an Attacker may cause an RCE by convincing a user to load a malicio…EPSS 0.21%7.8CVE-2025-23354Nvidia megatron-lm code injection vulnerabilityNVIDIA Megatron-LM for all platforms contains a vulnerability in the ensemble_classifer script where malicious data created by an attacker may cause …EPSS 0.24%7.8CVE-2025-23348Nvidia megatron-lm code injection vulnerabilityNVIDIA Megatron-LM for all platforms contains a vulnerability in the pretrain_gpt script, where malicious data created by an attacker may cause a cod…EPSS 0.24%7.8CVE-2025-23349Nvidia megatron-lm code injection vulnerabilityNVIDIA Megatron-LM for all platforms contains a vulnerability in the tasks/orqa/unsupervised/nq.py component, where an attacker may cause a code inje…EPSS 0.24%

Source: NIST National Vulnerability Database (record CVE-2025-23353), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.