Database/AI/ML frameworks & serving
NVIDIA NemoClaw: code injection in the migration command gives a local user execution as the tool's privileges
Impact
NVIDIA reports a code injection reachable through the migration command of NemoClaw for Linux, with possible code execution, data tampering, information disclosure and denial of service. A migration command typically runs during upgrade or state-move operations, so it is a path that gets invoked with elevated context on a node an operator considers trusted. A local user who can influence what that command consumes gets execution in that context rather than in their own. NVIDIA's vector is local with low privileges required and high attack complexity, and all three impact metrics are high. The record does not identify affected versions or the injected input.
Who can reach it
A local user on a host running NemoClaw, with low privileges. Not remotely reachable per NVIDIA's vector, and attack complexity is rated high.
What to do
Update NemoClaw to the fixed release named in NVIDIA's advisory (product-security bulletin 5872, shared with CVE-2026-65086); no fixed version appears in the record given here. Until the update is applied, limit local accounts on hosts where NemoClaw is installed and avoid running its migration command on nodes shared with untrusted users.
References
Related entries
- llama.cpp ggml RPC server: unvalidated tensor op and op_params in deserialize_tensorCVE-2026-78147 · llama.cpp ggml RPC server (deserialize_tensor op / op_params validation)Medium
- llama.cpp ggml RPC server: null pointer dereference in graph_compute kills the GPU workerCVE-2026-78148 · llama.cpp ggml RPC server (rpc_server::graph_compute)Medium
- BentoML: SSRF filter misses 100.64.0.0/10, so serving pods fetch from internal CGNAT hostsCVE-2026-78205 · BentoML make_safe_connect (SSRF address filter, RFC 6598 range)Medium
- vLLM: DeepStream backend misclassification skips pixel limits and lets unauthenticated video exhaust GPU decodeCVE-2026-78684 · vLLM (DeepStream GPU decode path, pixel-limit enforcement)Medium
- ONNX: symlink-following external-data write lets a local attacker append to victim-writable filesCVE-2026-49114 · ONNX Python library (save_external_data external-data path handling)Medium
- NVIDIA OpenShell: sandbox exec handler is vulnerable to OS command injection, breaking the sandbox boundaryCVE-2026-65086 · NVIDIA OpenShell for Linux (sandbox exec handler)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.