CVE-2026-61750
nicheInsecure Deserialization in NVIDIA Megatron Bridge Allows Local Code Execution
NVIDIA Megatron Bridge, the LLM training and post-training library in NVIDIA's NeMo ecosystem, contains a deserialization flaw (CWE-502) in which it deserializes untrusted data without validation. The CVSS vector (AV:L/PR:L/UI:N) indicates the flaw is triggered locally by a low-privileged attacker or process, meaning the realistic trigger is getting the framework to deserialize attacker-controlled serialized input such as a checkpoint or other artifact it processes locally, with no user interaction. A successful exploit yields high-impact code execution, data tampering, and information disclosure within the affected environment. Users of NVIDIA Megatron Bridge are affected; the advisory data provided does not specify affected or fixed version ranges. As of now there is no known exploitation: EPSS is low at 0.3%, the issue is not in CISA KEV, and no public proof-of-concept is known.
What to do: Check NVIDIA's PSIRT advisory for CVE-2026-61750 to identify affected and fixed Megatron Bridge releases and upgrade to a patched version. Because the flaw is in deserialization of untrusted data, avoid loading checkpoints, weights, or other serialized artifacts from untrusted or shared sources in training and evaluation pipelines until patched. In shared or multi-tenant GPU clusters, review which jobs deserialize third-party artifacts and restrict that surface as a mitigation.
| NVIDIA Megatron Bridge (NeMo Megatron Bridge) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
NVIDIA Megatron Bridge contains a vulnerability where an attacker could cause a deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure.
- Vendors
- nvidia
- Products
- nemo megatron bridge
- Weakness
- CWE-502
- Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.