Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 3

Количество 3

nvd логотип

CVE-2026-53805

около 2 месяцев назад

NVIDIA Spatial Intelligence Lab's (SIL) GEN3C contains an unauthenticated remote code execution vulnerability in the inference API server where the /request-inference and /seed-model endpoints deserialize raw HTTP request bodies using Python's pickle.loads() without authentication or input validation. Attackers can supply a crafted payload containing a __reduce__ gadget to the inference API port to achieve remote code execution as the inference process.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-478c-rj3v-9229

около 2 месяцев назад

NVIDIA Spatial Intelligence Lab's (SIL) GEN3C contains an unauthenticated remote code execution vulnerability in the inference API server where the /request-inference and /seed-model endpoints deserialize raw HTTP request bodies using Python's pickle.loads() without authentication or input validation. Attackers can supply a crafted payload containing a __reduce__ gadget to the inference API port to achieve remote code execution as the inference process.

CVSS3: 9.8
EPSS: Низкий
fstec логотип

BDU:2026-09243

около 2 месяцев назад

Уязвимость функции pickle.loads() нейросетевой модели видео для создания реалистичных видеороликов NVIDIA GEN3C, позволяющая нарушителю выполнить произвольный код

CVSS3: 9.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2026-53805

NVIDIA Spatial Intelligence Lab's (SIL) GEN3C contains an unauthenticated remote code execution vulnerability in the inference API server where the /request-inference and /seed-model endpoints deserialize raw HTTP request bodies using Python's pickle.loads() without authentication or input validation. Attackers can supply a crafted payload containing a __reduce__ gadget to the inference API port to achieve remote code execution as the inference process.

CVSS3: 9.8
1%
Низкий
около 2 месяцев назад
github логотип
GHSA-478c-rj3v-9229

NVIDIA Spatial Intelligence Lab's (SIL) GEN3C contains an unauthenticated remote code execution vulnerability in the inference API server where the /request-inference and /seed-model endpoints deserialize raw HTTP request bodies using Python's pickle.loads() without authentication or input validation. Attackers can supply a crafted payload containing a __reduce__ gadget to the inference API port to achieve remote code execution as the inference process.

CVSS3: 9.8
1%
Низкий
около 2 месяцев назад
fstec логотип
BDU:2026-09243

Уязвимость функции pickle.loads() нейросетевой модели видео для создания реалистичных видеороликов NVIDIA GEN3C, позволяющая нарушителю выполнить произвольный код

CVSS3: 9.8
1%
Низкий
около 2 месяцев назад

Уязвимостей на страницу