Database/AI/ML frameworks & serving
NVIDIA NemoClaw: OS command injection in the status and logs plugin commands
Impact
NemoClaw's status and logs plugin commands interpolate input into an OS command, so a crafted plugin or argument yields code execution, data tampering, information disclosure and denial of service. Status and log collection is the path operators reach for constantly and the one automation polls on a timer, which makes it a reliable trigger: an attacker who can influence a plugin name or log target gets their command run every time someone checks on the node. NVIDIA rates it 7.8 with high impact across all three axes.
Who can reach it
A local, low-privileged actor able to supply input to NemoClaw's status or logs plugin commands (CVSS AV:L, PR:L). Authentication required; no user interaction.
What to do
Update NemoClaw from the NVIDIA/NemoClaw GitHub repo. Versions 0 through 0.0.25 are affected per bulletin 5872; the fixed version differs per CVE, so read the Security Updates table for this one. The update replaces the tool on disk and takes effect for subsequent invocations; restart any monitoring automation or service that keeps a NemoClaw process resident.
References
Related entries
- NVIDIA NemoClaw: OS command injection in the NIM management componentCVE-2026-65090 · NVIDIA NemoClaw for Linux (NIM management component)High
- NVIDIA NemoClaw: OS command injection in the Telegram bridge componentCVE-2026-65096 · NVIDIA NemoClaw for Linux (Telegram bridge component)High
- NVIDIA NemoClaw: OS command injection through the command-line interfaceCVE-2026-65099 · NVIDIA NemoClaw for Linux (command-line interface)High
- PyTorch (flatbuffer model parsing, torch::load / parse_and_initialize_mobile_module): MALICIOUS MODEL FILE TO MEMORYNCVD-2025-019-pytorch-flatbuffer-model-parsing · PyTorch (flatbuffer model parsing, torch::load / parse_and_initialize_mobile_module)High
- LangChain (Web Research Retriever): SSRFCVE-2024-3095 · LangChain (Web Research Retriever)High
- SitemapLoader: nested sitemap entries skip restrict_to_same_domain, giving readable SSRFCVE-2026-72848 · langchain-community SitemapLoader (nested sitemap index entries)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.