Multiple high-severity deserialization vulnerabilities have been identified in widely used AI and analytics frameworks, including NVIDIA Isaac Lab, MooreThreads torch_musa, and NVIDIA Merlin components. These flaws allow attackers to exploit unsafe deserialization processes, potentially leading to remote code execution or denial-of-service conditions on affected systems. In the case of MooreThreads torch_musa, the vulnerability arises from the use of pickle.load() on user-controlled files without validation, enabling arbitrary code execution with the privileges of the victim process. Similarly, NVIDIA Isaac Lab and Merlin frameworks are affected by deserialization issues that could be exploited remotely, with Merlin's NVTabular and Transformers4Rec components specifically highlighted for their susceptibility to code execution and data tampering attacks.
Security advisories urge immediate patching, as these vulnerabilities are remotely exploitable and pose significant risks to enterprise environments. The affected products span various versions, and organizations using these frameworks are advised to review vendor guidance and apply available security updates to mitigate the threat. The vulnerabilities have been assigned high or critical CVSS scores, underscoring the urgency for remediation to prevent potential exploitation in production environments.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
NVIDIA's PSIRT disclosed CVE-2025-33210, a critical deserialization vulnerability in NVIDIA Isaac Lab with potential for remote code execution. The issue was confirmed to affect Isaac Lab and prompted guidance to update to the latest version and apply available security patches.
Proof-of-concept exploit code for CVE-2025-65213 was reported as publicly available on GitHub, increasing the likelihood of exploitation in the wild. The PoC relates to unsafe use of pickle.load() on user-controlled file paths in torch_musa.
A critical deserialization vulnerability, CVE-2025-65213, was published for all versions of MooreThreads torch_musa, affecting functions in the torch_musa.utils.compare_tool module that use unsafe pickle deserialization. The issue can be exploited remotely without privileges or user interaction to achieve arbitrary code execution.
NVIDIA released security patches for its Merlin framework to fix CVE-2025-33214 and CVE-2025-33213, two high-severity deserialization vulnerabilities affecting the NVTabular Workflow and Transformers4Rec Trainer components on Linux. The flaws could allow arbitrary code execution, denial of service, sensitive information disclosure, and data tampering.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
cvefeed.io
Open sourcecvefeed.io
Open sourcecybersecuritynews.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.