Improper Control of Code Generation in NVIDIA TensorRTLLM Leads to Code Execution
CVE-2026-24226 Published on July 14, 2026
NVIDIA TensorRT-LLM for Linux contains a vulnerability where an attacker could cause improper control of code generation. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure.
Vulnerability Analysis
CVE-2026-24226 is exploitable with local system access, requires user interaction and user privileges. This vulnerability is consided to have a high level of attack complexity. The potential impact of an exploit of this vulnerability is considered to be very high.
Weakness Type
Inclusion of Functionality from Untrusted Control Sphere
The software imports, requires, or includes executable functionality (such as a library) from a source that is outside of the intended control sphere.
Affected Versions
NVIDIA TensorRT-LLM:- Before and including v1.3.0 rc12 is affected.