Remote Code Execution Vulnerability in NVIDIA Megatron LM
CVE-2025-33247

7.8HIGH

Key Information:

Vendor

Nvidia

Vendor
CVE Published:
24 March 2026

What is CVE-2025-33247?

NVIDIA Megatron LM has a vulnerability in the quantization configuration loading process that can be leveraged for remote code execution. Exploiting this vulnerability may allow attackers to execute arbitrary code, potentially leading to unauthorized access, privilege escalation, information leaks, and manipulation of sensitive data.

Affected Version(s)

Megatron LM All platforms All versions prior to 0.15.3

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.