CVE-2025-33248 - CVE House
Back to Database
Status published High CVE-2025-33248

NVIDIA Megatron-LM contains a vulnerability in the hybrid conversion script...

Vulnerability Description

NVIDIA Megatron-LM contains a vulnerability in the hybrid conversion script where an Attacker may cause an RCE by convincing a user to load a maliciously crafted file. A successful exploit of this vulnerability may lead to code execution, escalation of privileges, information disclosure, and data tampering.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-33248

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

Megatron LM
Vulnerable Versions:
All versions prior to 0.15.3

Timeline

Official Publish: March 24th, 2026
Last Modified: March 25th, 2026
Added to House: July 22nd, 2026

CVSS Vectors

V3: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Weaknesses (CWE)