logo

CVE-2025-23298: Getting Remote Code Execution in NVIDIA Merlin

ID: 27f15fb3-3fa5-5784-a930-b59dddf17232

STIX ID: report--27f15fb3-3fa5-5784-a930-b59dddf17232

Feed Name: Zero Day Initiative (ZDI) Blog

Threat Score
65/100

Date Published: 2025-09-24

Date Updated: 2026-05-01

Author: Peter Girnus

...
...

This report outlines a critical vulnerability in ML model checkpoint deserialization (use of Python pickle) that can enable supply-chain and arbitrary code execution attacks. It offers targeted recommendations for developers (avoid pickle, use weights_only=True, prefer safetensors/ONNX, restrict trusted classes), organizations (audit provenance, sign models, sandbox loading), and the ML community (deprecate pickle, update torch, develop secure serialization standards).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.