CVE-2025-33239
Published: 18 February 2026
Summary
CVE-2025-33239 is a high-severity Code Injection (CWE-94) vulnerability in Nvidia Megatron-Bridge. Its CVSS base score is 7.8 (High).
Operationally, exploitation aligns with the MITRE ATT&CK technique Command and Scripting Interpreter (T1059); ranked at the 7.8th percentile by exploit likelihood (below the median); it is not currently listed in the CISA KEV catalog.
The strongest mitigations our analysis identified are NIST 800-53 SI-10 (Information Input Validation) and SI-2 (Flaw Remediation).
Threat & Defense at a Glance
Threat & Defense Details
Mitigating Controls (NIST 800-53 r5)AI
Directly validates and sanitizes malicious inputs to prevent code injection in the data merging tutorial.
Remediates the specific code injection flaw through timely patching as advised in NVIDIA and NVD advisories.
Enforces least privilege to limit the impact of privilege escalation resulting from successful code execution.
MITRE ATT&CK Enterprise TechniquesAI
Why these techniques?
Local code injection (CWE-94) directly enables arbitrary code execution via T1059 and facilitates privilege escalation via T1068.
NVD Description
NVIDIA Megatron Bridge contains a vulnerability in a data merging tutorial, where malicious input could cause a code injection. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, information disclosure, and data tampering.
Deeper analysisAI
CVE-2025-33239 is a code injection vulnerability (CWE-94) in a data merging tutorial within NVIDIA Megatron Bridge. The issue arises from malicious input that can lead to arbitrary code execution, with potential impacts including escalation of privileges, information disclosure, and data tampering. The vulnerability has a CVSS v3.1 base score of 7.8 (AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H) and was published on 2026-02-18.
A local attacker with low privileges can exploit this vulnerability with low attack complexity and no user interaction required. Successful exploitation might result in code execution, privilege escalation, information disclosure, and data tampering on the affected system.
Mitigation details are available in advisories from the National Vulnerability Database at https://nvd.nist.gov/vuln/detail/CVE-2025-33239, NVIDIA at https://nvidia.custhelp.com/app/answers/detail/a_id/5781, and CVE.org at https://www.cve.org/CVERecord?id=CVE-2025-33239.
Details
- CWE(s)