GHSL-2025-113: Insecure deserialization in NVIDIA-Merlin/Transformers4Rec could lead to RCE - CVE-2025-33213
NVIDIA-Merlin/Transformers4Rec v23.12.00 is affected by insecure deserialization in the loadmodeltrainerstatesfromcheckpoint function, which could allow an attacker to execute arbitrary code when loading malicious models.
Affected Software
Event History
Frequently Asked Questions
What is the severity of GHSL-2025-113?
The severity of GHSL-2025-113 is rated as 77, indicating a high risk associated with the vulnerability.
How do I fix GHSL-2025-113?
To fix GHSL-2025-113, update NVIDIA-Merlin/Transformers4Rec to the latest version that addresses the insecure deserialization issue.
What is the impact of GHSL-2025-113?
The impact of GHSL-2025-113 includes the potential for remote code execution if an attacker loads a malicious model.
Which versions of NVIDIA-Merlin/Transformers4Rec are affected by GHSL-2025-113?
NVIDIA-Merlin/Transformers4Rec version 23.12.00 is specifically affected by GHSL-2025-113.
What function in NVIDIA-Merlin/Transformers4Rec is vulnerable to GHSL-2025-113?
The load_model_trainer_states_from_checkpoint function is the vulnerable component in NVIDIA-Merlin/Transformers4Rec related to GHSL-2025-113.