CVE-2025-23353
NVIDIA Megatron-LM for all platforms contains a vulnerability in the msdp preprocessing script where malicious data created by an attacker may cause an injection.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.24%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
NVIDIA Megatron-LM for all platforms contains a vulnerability in the msdp preprocessing script where malicious data created by an attacker may cause an injection. A successful exploit of this vulnerability may lead to code execution, escalation of privileges, Information disclosure, and data tampering.
- CVSS 3.1
- 7.8 HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 0.24% probability · 15th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-94
- Affected
- nvidia/megatron-lm
- Source
- psirt@nvidia.com
References
- https://nvd.nist.gov/vuln/detail/CVE-2025-23353Technical Description
- https://nvidia.custhelp.com/app/answers/detail/a_id/5698Vendor Advisory
- https://www.cve.org/CVERecord?id=CVE-2025-23353Technical Description
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.