GPU VulnDB

Database/AI/ML frameworks & serving

NVIDIA OpenShell: a malicious gateway can inject OS commands into the connecting client

CVE-2026-65091AI/ML frameworks & servingcurated

Impact

OpenShell trusts what its gateway sends it far enough that a hostile or compromised gateway can inject operating system commands, giving code execution, data tampering and information disclosure on the machine running OpenShell. The direction of this one matters: the attacker is the far end of the connection, not a local tenant, so it converts a gateway takeover - or a redirected/spoofed gateway endpoint - into execution on every client that connects. On a fleet where OpenShell clients run on GPU nodes or on operator workstations with cluster credentials, one bad gateway reaches all of them. NVIDIA scores it with user interaction required (UI:R), so something on the client side has to initiate or accept the interaction.

Who can reach it

Network, no authentication on the attacker's side (CVSS AV:N/PR:N/UI:R): whoever controls or can impersonate the gateway an OpenShell client connects to, with some client-side interaction needed.

What to do

Update OpenShell to v0.0.34 as directed by NVIDIA bulletin 5872 (affected: 0 through 0.0.33, all platforms; clone or update from the NVIDIA/OpenShell GitHub repository). Because the exposure is client-side, update every host that runs an OpenShell client, not only the gateway, and restart the service. Until updated, restrict clients to gateway endpoints you operate.

References

Related entries

All AI/ML frameworks & serving entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.