CVE-2026-53805
CRITICAL
NVIDIA SIL GEN3C Unauthenticated RCE via Pickle Deserialization in Inference API
Record summary
CVE-2026-53805 has a selected CVSS score of 9.3 (critical); EIP currently links 1 repository PoC.
Description
NVIDIA Spatial Intelligence Lab's (SIL) GEN3C contains an unauthenticated remote code execution vulnerability in the inference API server where the /request-inference and /seed-model endpoints deserialize raw HTTP request bodies using Python's pickle.loads() without authentication or input validation. Attackers can supply a crafted payload containing a __reduce__ gadget to the inference API port to achieve remote code execution as the inference process.
Description source: CVE List
Exploitation context
Available material
- Repository PoCs
- 1
CISA SSVC decision
ExploitationNone
AutomatableYes
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Jun 17, 2026 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Default status: affected | CVE List | Before db2ffe12ced12ddafcec5e0422ee46ce8520746b | affected |
Proofs of concept
1Repository PoCs
GitHubHORKimhab/CVE-2026-42055Repository PoCby HORKimhabStars: 0Not analyzed3 files
References
5github.compatch
https://github.com/nv-tlabs/GEN3C/commit/db2ffe12ced12ddafcec5e0422ee46ce8520746b github.comissue tracking
https://github.com/nv-tlabs/GEN3C/pull/62 github.comissue tracking
https://github.com/nv-tlabs/GEN3C/pull/63 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2026-53805 vulncheck.comThird-party advisory
https://www.vulncheck.com/advisories/nvidia-sil-gen3c-unauthenticated-rce-via-pickle-deserialization-in-inference-api