Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-478c-rj3v-9229

Опубликовано: 17 июн. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 9.3
CVSS3: 9.8

Описание

NVIDIA Spatial Intelligence Lab's (SIL) GEN3C contains an unauthenticated remote code execution vulnerability in the inference API server where the /request-inference and /seed-model endpoints deserialize raw HTTP request bodies using Python's pickle.loads() without authentication or input validation. Attackers can supply a crafted payload containing a reduce gadget to the inference API port to achieve remote code execution as the inference process.

NVIDIA Spatial Intelligence Lab's (SIL) GEN3C contains an unauthenticated remote code execution vulnerability in the inference API server where the /request-inference and /seed-model endpoints deserialize raw HTTP request bodies using Python's pickle.loads() without authentication or input validation. Attackers can supply a crafted payload containing a reduce gadget to the inference API port to achieve remote code execution as the inference process.

EPSS

Процентиль: 55%
0.00872
Низкий

9.3 Critical

CVSS4

9.8 Critical

CVSS3

Дефекты

CWE-502

Связанные уязвимости

CVSS3: 9.8
nvd
около 2 месяцев назад

NVIDIA Spatial Intelligence Lab's (SIL) GEN3C contains an unauthenticated remote code execution vulnerability in the inference API server where the /request-inference and /seed-model endpoints deserialize raw HTTP request bodies using Python's pickle.loads() without authentication or input validation. Attackers can supply a crafted payload containing a __reduce__ gadget to the inference API port to achieve remote code execution as the inference process.

CVSS3: 9.8
fstec
около 2 месяцев назад

Уязвимость функции pickle.loads() нейросетевой модели видео для создания реалистичных видеороликов NVIDIA GEN3C, позволяющая нарушителю выполнить произвольный код

EPSS

Процентиль: 55%
0.00872
Низкий

9.3 Critical

CVSS4

9.8 Critical

CVSS3

Дефекты

CWE-502