Remote Code Execution Vulnerability in NVIDIA Megatron-LM
CVE-2025-33248
7.8HIGH
What is CVE-2025-33248?
NVIDIA Megatron-LM is susceptible to a Remote Code Execution vulnerability due to a flaw in its hybrid conversion script. An attacker could exploit this weakness by persuading a user to open a specially crafted file. If successfully exploited, this vulnerability allows for code execution, enabling the attacker to potentially escalate privileges, disclose sensitive information, and tamper with data. Users of NVIDIA's Megatron-LM should ensure they are aware of this risk and apply necessary security measures to mitigate potential threats.
Affected Version(s)
Megatron LM All platforms All versions prior to 0.15.3