Record summary

CVE-2026-53805 has a selected CVSS score of 9.3 (critical); EIP currently links 1 repository PoC.

Description

NVIDIA Spatial Intelligence Lab's (SIL) GEN3C contains an unauthenticated remote code execution vulnerability in the inference API server where the /request-inference and /seed-model endpoints deserialize raw HTTP request bodies using Python's pickle.loads() without authentication or input validation. Attackers can supply a crafted payload containing a __reduce__ gadget to the inference API port to achieve remote code execution as the inference process.

Description source: CVE List

Exploitation context

Available material

Repository PoCs
1

CISA SSVC decision

ExploitationNone
AutomatableYes
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated Jun 17, 2026 · Source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus

Default status: affected

CVE ListBefore db2ffe12ced12ddafcec5e0422ee46ce8520746baffected

Proofs of concept

1

Repository PoCs

GitHubHORKimhab/CVE-2026-42055Repository PoCby HORKimhabStars: 0Not analyzed3 files

5.3 KiB · linked to 14 vulnerabilities

GitHub

PoC details

References

5