megatron-bridge@0.4.0

Megatron Bridge: Training Recipes for Megatron-based LLM and VLM models

  • latest version

    0.5.1

  • latest non vulnerable version

  • first published

    11 months ago

  • latest version published

    17 days ago

  • licenses detected

  • Direct Vulnerabilities

    Known vulnerabilities in the megatron-bridge package. This does not include vulnerabilities belonging to this package’s dependencies.

    Fix vulnerabilities automatically

    Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.

    Fix for free
    VulnerabilityVulnerable Version
    • H
    Deserialization of Untrusted Data

    megatron-bridge is a Megatron Bridge: Training Recipes for Megatron-based LLM and VLM models

    Affected versions of this package are vulnerable to Deserialization of Untrusted Data via improper validation of allowed inputs. An attacker can execute arbitrary code, escalate privileges, tamper with data, and disclose information by providing specially crafted input.

    How to fix Deserialization of Untrusted Data?

    Upgrade megatron-bridge to version 0.4.1 or higher.

    [0,0.4.1)
    • H
    Deserialization of Untrusted Data

    megatron-bridge is a Megatron Bridge: Training Recipes for Megatron-based LLM and VLM models

    Affected versions of this package are vulnerable to Deserialization of Untrusted Data in the deserialization process. An attacker can execute arbitrary code, escalate privileges, tamper with data, and access sensitive information by providing specially crafted input that is deserialized without proper validation.

    How to fix Deserialization of Untrusted Data?

    Upgrade megatron-bridge to version 0.4.1 or higher.

    [0,0.4.1)
    • H
    Deserialization of Untrusted Data

    megatron-bridge is a Megatron Bridge: Training Recipes for Megatron-based LLM and VLM models

    Affected versions of this package are vulnerable to Deserialization of Untrusted Data in the deserialization process. An attacker can execute arbitrary code, escalate privileges, tamper with data, and access sensitive information by providing specially crafted input that is deserialized without proper validation.

    How to fix Deserialization of Untrusted Data?

    Upgrade megatron-bridge to version 0.4.1 or higher.

    [0,0.4.1)
    • H
    Deserialization of Untrusted Data

    megatron-bridge is a Megatron Bridge: Training Recipes for Megatron-based LLM and VLM models

    Affected versions of this package are vulnerable to Deserialization of Untrusted Data via the deserialization process. An attacker can execute arbitrary code, escalate privileges, tamper with data, and access sensitive information by providing specially crafted data to be deserialized.

    How to fix Deserialization of Untrusted Data?

    Upgrade megatron-bridge to version 0.4.1 or higher.

    [0,0.4.1)
    • H
    Server-side Request Forgery (SSRF)

    megatron-bridge is a Megatron Bridge: Training Recipes for Megatron-based LLM and VLM models

    Affected versions of this package are vulnerable to Server-side Request Forgery (SSRF) via the request process. An attacker can access internal resources and potentially disclose sensitive information by tricking the application into making unauthorized requests on their behalf.

    How to fix Server-side Request Forgery (SSRF)?

    Upgrade megatron-bridge to version 0.4.1 or higher.

    [0,0.4.1)
    • H
    Deserialization of Untrusted Data

    megatron-bridge is a Megatron Bridge: Training Recipes for Megatron-based LLM and VLM models

    Affected versions of this package are vulnerable to Deserialization of Untrusted Data in the process responsible for dynamically managing code resources. An attacker can execute arbitrary code, escalate privileges, tamper with data, and access sensitive information by providing crafted input that is improperly handled during code resource management.

    How to fix Deserialization of Untrusted Data?

    Upgrade megatron-bridge to version 0.4.1 or higher.

    [0,0.4.1)
    • H
    Deserialization of Untrusted Data

    megatron-bridge is a Megatron Bridge: Training Recipes for Megatron-based LLM and VLM models

    Affected versions of this package are vulnerable to Deserialization of Untrusted Data via the deserialization process. An attacker can execute arbitrary code, escalate privileges, tamper with data, and access sensitive information by providing specially crafted input that is deserialized without proper validation.

    How to fix Deserialization of Untrusted Data?

    Upgrade megatron-bridge to version 0.4.1 or higher.

    [0,0.4.1)
    • H
    Deserialization of Untrusted Data

    megatron-bridge is a Megatron Bridge: Training Recipes for Megatron-based LLM and VLM models

    Affected versions of this package are vulnerable to Deserialization of Untrusted Data via the deserialization process. An attacker can execute arbitrary code, escalate privileges, tamper with data, and access sensitive information by providing specially crafted untrusted data.

    How to fix Deserialization of Untrusted Data?

    Upgrade megatron-bridge to version 0.4.1 or higher.

    [0,0.4.1)
    • H
    Arbitrary Code Injection

    megatron-bridge is a Megatron Bridge: Training Recipes for Megatron-based LLM and VLM models

    Affected versions of this package are vulnerable to Arbitrary Code Injection in the code generation process. An attacker can execute arbitrary code, escalate privileges, tamper with data, and access sensitive information by providing crafted input that is improperly handled during code generation.

    How to fix Arbitrary Code Injection?

    Upgrade megatron-bridge to version 0.4.1 or higher.

    [0,0.4.1)
    • H
    Arbitrary Code Injection

    megatron-bridge is a Megatron Bridge: Training Recipes for Megatron-based LLM and VLM models

    Affected versions of this package are vulnerable to Arbitrary Code Injection via the deserialization process. An attacker can execute arbitrary code, escalate privileges, tamper with data, and disclose information by providing specially crafted input that is deserialized without proper validation.

    How to fix Arbitrary Code Injection?

    Upgrade megatron-bridge to version 0.4.1 or higher.

    [0,0.4.1)
    • H
    Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection')

    megatron-bridge is a Megatron Bridge: Training Recipes for Megatron-based LLM and VLM models

    Affected versions of this package are vulnerable to Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') in the process responsible for dynamically managing code resources. An attacker can execute arbitrary code, escalate privileges, tamper with data, and disclose sensitive information by supplying crafted input that is improperly handled during code resource management.

    How to fix Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection')?

    Upgrade megatron-bridge to version 0.4.1 or higher.

    [0,0.4.1)