GPU VulnDB

Database/AI/ML frameworks & serving

NVIDIA NemoClaw: code injection in the migration command gives a local user execution as the tool's privileges

CVE-2026-65082AI/ML frameworks & servingcurated

Impact

NVIDIA reports a code injection reachable through the migration command of NemoClaw for Linux, with possible code execution, data tampering, information disclosure and denial of service. A migration command typically runs during upgrade or state-move operations, so it is a path that gets invoked with elevated context on a node an operator considers trusted. A local user who can influence what that command consumes gets execution in that context rather than in their own. NVIDIA's vector is local with low privileges required and high attack complexity, and all three impact metrics are high. The record does not identify affected versions or the injected input.

Who can reach it

A local user on a host running NemoClaw, with low privileges. Not remotely reachable per NVIDIA's vector, and attack complexity is rated high.

What to do

Update NemoClaw to the fixed release named in NVIDIA's advisory (product-security bulletin 5872, shared with CVE-2026-65086); no fixed version appears in the record given here. Until the update is applied, limit local accounts on hosts where NemoClaw is installed and avoid running its migration command on nodes shared with untrusted users.

References

Related entries

All AI/ML frameworks & serving entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.