NVIDIA Merlin Transformers4Rec Code Injection Vulnerability Allowing Privilege Escalation and Code Execution

Vulnerability

A code injection vulnerability has been identified in NVIDIA Merlin Transformers4Rec, affecting all platforms. This vulnerability allows an attacker to inject malicious code, which could be executed, potentially leading to unauthorized code execution, escalation of privileges, information disclosure, and data tampering.

Impact

Exploitation of this vulnerability could result in unauthorized code execution, elevated privileges, disclosure of sensitive information, and unauthorized modification of data.

Remediation

Users are advised to update to any code branch that includes commit 27ddd49. The updated version can be found in the NVIDIA-Merlin/Transformers4Rec repository on GitHub.

Added: Jan 20, 2026, 7:10 PM
Updated: Jan 20, 2026, 7:10 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
10.0
exploitability
3.3
remediation
0.0
relevance
2.2
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.