NVIDIA Merlin Transformers4Rec: Improper deserialization of untrusted data reaches code execution and information
Impact
Improper deserialization of untrusted data reaches code execution and information disclosure. In an AI datacenter this is the model-and-data supply chain problem: the code runs with whatever the training or inference job holds, which is usually a GPU, a service account, and mounted object storage credentials.
Who can reach it
Requires the job to load an attacker-influenced artifact - a checkpoint, .nemo file, config, tokenizer or dataset. Any pipeline that pulls from a public model hub, a customer bucket, or a tenant-supplied path is in scope.
What to do
Bump the package to the fixed version in bulletin 5838 and rebuild every training/inference image that embeds it. Cost: image rebuild and job restart; no host driver or firmware change. The durable control is refusing to deserialize untrusted checkpoints at all - prefer safetensors-style formats and treat pickle-bearing artifacts as executable code.
References
Related entries
- NVIDIA Merlin Transformers4Rec: The Trainer component deserializes untrusted data, reaching code executionCVE-2025-33213 · NVIDIA Merlin Transformers4RecHigh
- NVIDIA Merlin Transformers4Rec: A Python dependency permits code injection into the recommender training jobCVE-2025-23298 · NVIDIA Merlin Transformers4RecHigh
- BioNeMo Framework: RCE via malicious pickled dataCVE-2026-24165 · BioNeMo FrameworkHigh
- NVIDIA Cumulus Linux: Improper privilege management in the user-management component lets an unprivileged switch userCVE-2026-24183 · NVIDIA Cumulus LinuxHigh
- GPU Display Driver: Local privesc (insufficient permission checks)CVE-2026-24190 · GPU Display DriverHigh
- GPU Display Driver: Local privesc (synchronization issue)CVE-2026-24191 · GPU Display DriverHigh
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.