GPU VulnDB

Database/AI/ML frameworks & serving

NVIDIA NemoClaw: sensitive information visible in process invocation leads to information disclosure

CVE-2026-65088AI/ML frameworks & servingcurated

Impact

NVIDIA describes invocation of a process using visible sensitive information, with information disclosure as the consequence. In practice this class of flaw means secrets passed on a command line, which any local user can read from the process table - on a shared or multi-tenant GPU host that is a much wider audience than the account that owns the tool. CVSS scores it local with low privileges and no user interaction, high confidentiality impact and no integrity or availability impact (5.5). The record does not say which values are exposed; treat anything NemoClaw was configured with as potentially readable.

Who can reach it

Any local user on the host running NemoClaw who can observe the process table while it runs (CVSS AV:L/AC:L/PR:L/UI:N). Low-privileged authenticated local access is enough.

What to do

Update NemoClaw to the fixed release from NVIDIA advisory bundle 5872 - the record names no fixed version, so read the advisory. Rotate any secrets NemoClaw was invoked with, since exposure to co-tenants on the same host cannot be undone by the patch.

References

Related entries

All AI/ML frameworks & serving entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.