PT-2026-50511 · Nvidia · Gen3C

·

CVE-2026-53805

·

Published

2026-06-11

·

Updated

2026-07-17

CVSS v4.0

10

Critical

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions NVIDIA Spatial Intelligence Lab's (SIL) GEN3C (affected versions not specified)
Description The inference API server contains an unauthenticated remote code execution flaw. The endpoints '/request-inference' and '/seed-model' deserialize raw HTTP request bodies using the Python pickle.loads() function without requiring authentication or performing input validation. An attacker can send a crafted payload containing a reduce gadget to the inference API port to execute arbitrary code with the privileges of the inference process.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

RCE

Deserialization of Untrusted Data

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-09243
CVE-2026-53805

Affected Products

Gen3C