CVE-2025-33233
7.8NVIDIA · Merlin Transformers4Rec
NVIDIA Merlin Transformers4Rec is susceptible to code injection, which can lead to unauthorized code execution, privilege escalation, information disclosure, and data tampering.
Executive summary
A code injection vulnerability in NVIDIA Merlin Transformers4Rec poses a significant risk of unauthorized code execution and complete system compromise for local users.
Vulnerability
This vulnerability involves improper control of code generation, categorized as CWE-94, allowing a local authenticated attacker to perform code injection. The attack vector requires local access and low privileges to trigger the flaw.
Business impact
The potential for code execution and privilege escalation creates a severe security risk, potentially allowing an attacker to gain full control over the host environment. With a CVSS score of 7.8, this high-severity flaw could lead to catastrophic data breaches, unauthorized modification of sensitive datasets, and significant operational disruption.
Remediation
Immediate Action: Review the NVIDIA security bulletin (a_id/5761) and update to a version that incorporates commit 27ddd49 or apply the specific patch provided by the vendor.
Proactive Monitoring: Monitor system logs for unusual process execution or unauthorized modifications to application codebases and configuration files.
Compensating Controls: Restrict local system access to authorized personnel only and implement strict principle of least privilege policies to minimize the potential for an attacker to initiate the injection process.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Given the severity of potential impact, administrators should prioritize verifying the current version of the Merlin Transformers4Rec library against the provided commit identifier. Applying the fix is essential to prevent local attackers from escalating privileges or compromising the integrity of the data processing environment.