CVE-2025-33213

8.8

NVIDIA · Merlin Transformers4Rec

NVIDIA Merlin Transformers4Rec for Linux is vulnerable to a deserialization flaw in the Trainer component, which may lead to remote code execution or data tampering.

Executive summary

A critical deserialization vulnerability in NVIDIA Merlin Transformers4Rec allows for potential remote code execution, denial of service, and data tampering.

Vulnerability

This vulnerability is caused by insecure deserialization of untrusted data within the Trainer component. According to the CVSS vector, this flaw is exploitable by an unauthenticated attacker, though it requires user interaction to trigger the malicious payload.

Business impact

The potential for remote code execution poses a severe threat to the confidentiality, integrity, and availability of affected systems. A successful exploit could allow an attacker to gain unauthorized control over the environment, leading to data exfiltration or full system compromise. With a CVSS score of 8.8, this vulnerability is classified as High severity and requires prompt attention to prevent significant operational disruption.

Remediation

Immediate Action: Review the NVIDIA security bulletin (a_id/5739) and apply the necessary updates or patches as soon as they become available. If a formal release is not available, verify if applying commit 876f19e to your local source code is feasible.

Proactive Monitoring: Monitor system logs for unusual process executions or unexpected network traffic originating from the machine learning pipeline environment.

Compensating Controls: Implement strict input validation and access controls to ensure that only trusted data sources are processed by the Trainer component.

Exploitation status

Public Exploit Available: Unknown.

Analyst recommendation

Given the potential for remote code execution, security teams should treat this vulnerability with high urgency. Prioritize the identification of all instances of NVIDIA Merlin Transformers4Rec within the infrastructure and prepare to deploy the vendor-provided fix immediately upon release. Maintaining a rigorous patching cycle for machine learning libraries is essential to mitigating this category of risk.

More NVIDIA CVEs

Sources