Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-53805

Опубликовано: 17 июн. 2026
Источник: nvd
CVSS3: 9.8
EPSS Низкий

Описание

NVIDIA Spatial Intelligence Lab's (SIL) GEN3C contains an unauthenticated remote code execution vulnerability in the inference API server where the /request-inference and /seed-model endpoints deserialize raw HTTP request bodies using Python's pickle.loads() without authentication or input validation. Attackers can supply a crafted payload containing a reduce gadget to the inference API port to achieve remote code execution as the inference process.

EPSS

Процентиль: 55%
0.00872
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-502

Связанные уязвимости

CVSS3: 9.8
github
около 2 месяцев назад

NVIDIA Spatial Intelligence Lab's (SIL) GEN3C contains an unauthenticated remote code execution vulnerability in the inference API server where the /request-inference and /seed-model endpoints deserialize raw HTTP request bodies using Python's pickle.loads() without authentication or input validation. Attackers can supply a crafted payload containing a __reduce__ gadget to the inference API port to achieve remote code execution as the inference process.

CVSS3: 9.8
fstec
около 2 месяцев назад

Уязвимость функции pickle.loads() нейросетевой модели видео для создания реалистичных видеороликов NVIDIA GEN3C, позволяющая нарушителю выполнить произвольный код

EPSS

Процентиль: 55%
0.00872
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-502