Database/AI/ML frameworks & serving
NVIDIA NemoClaw: installation process executes untrusted code
Impact
The installer can be made to execute code an attacker controls, and installs of this kind normally run with elevated privileges on the node being provisioned. NVIDIA lists code execution, privilege escalation, data tampering, information disclosure and denial of service as outcomes. On a GPU fleet this matters most during provisioning and upgrade windows, when the same install path runs unattended across many nodes at once, so one poisoned install source reaches the whole batch. The record does not describe the specific input that gets trusted, so treat the exposure as install-time rather than steady-state.
Who can reach it
Network-adjacent attacker able to influence what the installation process fetches or reads (CVSS AV:N/PR:N/AC:H). No authentication stated, but the high attack complexity indicates conditions the attacker does not fully control.
What to do
Follow NVIDIA product-security bulletin 5872 for the fixed release; the CVE record names no fixed version. Until then, run NemoClaw installs only from a verified local mirror over a trusted path and re-run the install once a patched package is available. No node reboot is implied by the record.
References
Related entries
- NVIDIA NemoClaw: deployment process fails to validate certificates properlyCVE-2026-65084 · NVIDIA NemoClaw for Linux (deployment process, TLS certificate validation)High
- NVIDIA NemoClaw: weak authentication in the remote-access helper workflowCVE-2026-65098 · NVIDIA NemoClaw for Linux (remote-access helper workflow)High
- NVIDIA NemoClaw: inference service comes up without authentication, reachable from the adjacent networkCVE-2026-65105 · NVIDIA NemoClaw for Linux (inference server setup)High
- ClearML client SDK: Deserialization of untrusted dataCVE-2024-24590 · ClearML client SDKHigh
- ClearML client SDK: Path traversal — a malicious dataset writes arbitrary files on the consumerCVE-2024-24591 · ClearML client SDKHigh
- Keras (`utils.get_file`): Path traversal in tar extraction in 3.11.3 (incomplete fix)CVE-2025-12638 · Keras (`utils.get_file`)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.