NVIDIA Merlin Transformers4Rec Code Injection Vulnerability Allowing Code Execution and Privilege Escalation

Vulnerability

A code injection vulnerability has been identified in NVIDIA Merlin Transformers4Rec, affecting all platforms. This issue arises from a vulnerability in a Python dependency, which an attacker could exploit to inject malicious code. Successful exploitation may lead to unauthorized code execution, escalation of privileges, information disclosure, and data tampering.

Impact

Exploitation of this vulnerability could result in unauthorized code execution, elevated privileges, disclosure of sensitive information, and unauthorized modification of data.

Remediation

Users are advised to update to any version of NVIDIA Merlin Transformers4Rec that includes the GitHub commit b7eaea5. For more information, visit the NVIDIA Product Security page.

Added: Aug 13, 2025, 9:48 PM
Updated: Aug 13, 2025, 9:48 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
5.2
remediation
7.7
relevance
0.3
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.