CVE-2025-33233 HIGH

CVE-2025-33233

Vendor Nvidia
Product Merlin Transformers4Rec
Weakness CWE-94 · Code injection
Published January 20, 2026
Last update January 20, 2026

CVSS base score

7.8/10
Attack vector Local
Attack complexity Low
Privileges required Low
User interaction None
Confidentiality High
Integrity High

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

What the vulnerability does

01Description

NVIDIA Merlin Transformers4Rec for all platforms contains a vulnerability where an attacker could cause code injection. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, information disclosure, and data tampering.

Key dates

02Disclosure timeline

January 20, 2026 CVE published
January 20, 2026 Record updated