GPU VulnDB

Database/AI/ML frameworks & serving

NVIDIA NemoClaw: insufficiently protected credentials allow information disclosure and data tampering

CVE-2026-65087AI/ML frameworks & servingcurated

Impact

NVIDIA states that NemoClaw insufficiently protects credentials, and that a successful exploit might lead to information disclosure and data tampering. Credentials handled by AI tooling on a GPU fleet are usually the keys to model registries, object storage or downstream API endpoints, so exposure tends to be worth more than the host it was read from. The record gives no detail on where the credentials are stored or which principal can read them - CVSS scores it local, low-privilege, requiring user interaction, with high confidentiality and low integrity impact (5.6). Do not assume the exposure is limited to the local machine until the advisory says so.

Who can reach it

A local, low-privileged user on the host running NemoClaw, plus user interaction (CVSS AV:L/AC:L/PR:L/UI:R). Some authenticated local access is required.

What to do

Update NemoClaw to the fixed release listed in NVIDIA advisory bundle 5872; the record does not name a fixed version, so take it from the advisory. Because the issue concerns exposed credentials, rotate any credentials NemoClaw held after patching - patching alone does not undo an exposure that already happened.

References

Related entries

All AI/ML frameworks & serving entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.