Database/AI/ML frameworks & serving
NVIDIA OpenShell: a malicious gateway can inject OS commands into the connecting client
Impact
OpenShell trusts what its gateway sends it far enough that a hostile or compromised gateway can inject operating system commands, giving code execution, data tampering and information disclosure on the machine running OpenShell. The direction of this one matters: the attacker is the far end of the connection, not a local tenant, so it converts a gateway takeover - or a redirected/spoofed gateway endpoint - into execution on every client that connects. On a fleet where OpenShell clients run on GPU nodes or on operator workstations with cluster credentials, one bad gateway reaches all of them. NVIDIA scores it with user interaction required (UI:R), so something on the client side has to initiate or accept the interaction.
Who can reach it
Network, no authentication on the attacker's side (CVSS AV:N/PR:N/UI:R): whoever controls or can impersonate the gateway an OpenShell client connects to, with some client-side interaction needed.
What to do
Update OpenShell to v0.0.34 as directed by NVIDIA bulletin 5872 (affected: 0 through 0.0.33, all platforms; clone or update from the NVIDIA/OpenShell GitHub repository). Because the exposure is client-side, update every host that runs an OpenShell client, not only the gateway, and restart the service. Until updated, restrict clients to gateway endpoints you operate.
References
Related entries
- ChromaDB (Rust): Missing authorization validationCVE-2026-8828 · ChromaDB (Rust)High
- vLLM OpenAI-compatible server (qwen3_coder tool-call parser): Code execution inside the serving process, which on a GPUNCVD-2025-017-vllm-openai-compatible-server-qw · vLLM OpenAI-compatible server (qwen3_coder tool-call parser)High
- vLLM (multimodal prompt embeddings, sparse tensor validation): This is the advisory saying the earlier fix did notNCVD-2026-043-vllm-multimodal-prompt-embedding · vLLM (multimodal prompt embeddings, sparse tensor validation)High
- MLflow (statsmodels flavor, MLFLOW_ALLOW_PICKLE_DESERIALIZATION guard): SECURITY CONTROL BYPASS LEADING TO RCE: theNCVD-2026-054-mlflow-statsmodels-flavor-mlflow · MLflow (statsmodels flavor, MLFLOW_ALLOW_PICKLE_DESERIALIZATION guard)High
- Pure Storage FlashArray authentication input validation: Malformed input during authentication takes the FlashArrayCVE-2025-0051 · Pure Storage FlashArray authentication input validationHigh
- Ollama: malformed base64 image data crashes the model runner via null pointer dereferenceCVE-2025-15514 · Ollama (multi-modal image handling in /api/chat)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.