NVIDIA Isaac Lab Deserialization Vulnerability Leading to Code Execution

Vulnerability

A deserialization vulnerability has been identified in NVIDIA Isaac Lab, which is part of the NVIDIA Isaac Sim framework. This vulnerability allows for code execution if successfully exploited. It affects all versions of Isaac Lab prior to 2.3.0.

Impact

Exploitation of this vulnerability could result in unauthorized code execution within the application.

Remediation

Users are advised to update to the latest version of NVIDIA Isaac Lab, available on the NVIDIA Isaac Lab GitHub releases page. For more information, visit the NVIDIA Product Security page.

Added: Dec 16, 2025, 7:20 PM
Updated: Dec 16, 2025, 7:20 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
10.0
exploitability
5.2
remediation
7.7
relevance
1.4
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.