ZeroHour
ZDI Published Advisoriespublished ()ingested

ZDI-26-564: NVIDIA Transformers4Rec load_model_trainer_states_from_checkpoint Deserialization of Untrusted Data Remote Code Execution Vulnerability

lowAdvisoryimportance 18CVE-2026-24232
AI summary · glm-5.3-flash

ZDI discloses CVE-2026-24232, a CVSS 7.8 deserialization RCE in NVIDIA Transformers4Rec's load_model_trainer_states_from_checkpoint function.

The Zero Day Initiative published ZDI-26-564, a deserialization of untrusted data vulnerability in NVIDIA Transformers4Rec. Remote code execution is possible, but exploitation requires user interaction such as visiting a malicious page or opening a malicious file. The flaw is tracked as CVE-2026-24232 with a CVSS score of 7.8.

  • Insecure deserialization RCE in NVIDIA Transformers4Rec checkpoint loading
  • User interaction required (malicious page or file)
  • CVSS 7.8, assigned CVE-2026-24232, disclosed via ZDI-26-564
VendorsNVIDIA
OrganizationsZero Day Initiative

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-24232
NVIDIA Tranformers4Rec contains a vulnerability where an attacker could cause improper deserialization of untrusted data.

NVIDIA Tranformers4Rec contains a vulnerability where an attacker could cause improper deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure.

NVD description · AI analysis pending
4.3<1%
Full article

This vulnerability allows remote attackers to execute arbitrary code on affected installations of NVIDIA Transformers4Rec. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-24232.

This source does not provide full text. Read it at zerodayinitiative.com.