Megatron-Bridge: RCE via unsafe deserialization of untrusted model and config artifacts
CVSS 7.8CVE-2026-24240NVIDIA / GPU stack+6 more CVEscurated
Impact
Loading an attacker-supplied checkpoint, weight file or config lets arbitrary code run with the privileges of the training job; NVIDIA advisory 5841 split this one deserialization class across 7 CVE ids covering separate load paths, all fixed together.
Who can reach it
Malicious checkpoint
What to do
Upgrade Megatron-Bridge to the version fixed in NVIDIA advisory 5841 and rebuild training images; only load model artifacts from trusted sources.
Also covers 6 CVEs
The vendor assigned a separate id to each affected code path. They share this advisory, this score and this fix, so they are one entry here.
CVE-2026-24243CVE-2026-24244CVE-2026-24245CVE-2026-24247CVE-2026-24248CVE-2026-24251
References
Related entries
- Megatron-Bridge: SSRF in file operationsCVE-2026-24242 · Megatron-BridgeHigh
- Megatron-Bridge: Validation bypass via incorrect type comparisonCVE-2026-24246 · Megatron-BridgeHigh
- Megatron-Bridge: RCE via unsafe evaluation of loaded configCVE-2026-24249 · Megatron-BridgeHigh
- Megatron-Bridge: code injection via malicious input in the data merging and data shuffling tutorialsCVE-2025-33239 · Megatron-BridgeHigh
- NeMo Framework: Command injection in script processingCVE-2026-24250 · NeMo FrameworkHigh
- NVIDIA NeMo Framework: OS command injection reaches code execution with the job's privilegesCVE-2026-24252 · NVIDIA NeMo FrameworkHigh
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.