#ml-security

[ follow ]
Information security
fromZero Day Initiative
2 days ago

Zero Day Initiative - CVE-2025-23298: Getting Remote Code Execution in NVIDIA Merlin

Avoid pickle-based deserialization and enforce secure model-loading: use weights_only, restrict classes, sandbox loading, sign and audit models, and prefer safer formats.
[ Load more ]