ZDI-26-564: NVIDIA Transformers4Rec load_model_trainer_states_from_checkpoint Deserialization of Untrusted Data Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on affected installations of NVIDIA Transformers4Rec. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-24232.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-26-564?
The ZDI-26-564 vulnerability has a CVSS rating of 7.8, indicating a high severity risk.
How do I fix ZDI-26-564?
To fix ZDI-26-564, users should update their NVIDIA Transformers4Rec to the latest version provided by NVIDIA.
What type of vulnerability is ZDI-26-564?
ZDI-26-564 is a remote code execution vulnerability caused by deserialization of untrusted data in NVIDIA Transformers4Rec.
What conditions are necessary for ZDI-26-564 to be exploited?
Exploitation of ZDI-26-564 requires user interaction, such as visiting a malicious page or opening a malicious file.
Who is affected by the ZDI-26-564 vulnerability?
Users with installations of NVIDIA Transformers4Rec are affected by the ZDI-26-564 vulnerability.