GPU VulnDB

Database/AI/ML frameworks & serving

NVIDIA NemoClaw: OS command injection in the Telegram bridge component

CVE-2026-65096AI/ML frameworks & servingcurated

Impact

The Telegram bridge in NemoClaw passes input into an OS command without adequate sanitisation, which NVIDIA says may lead to code execution, privilege escalation, information disclosure and data tampering. The bridge is a notification path, so the input it handles arrives from outside the node - that makes it the most externally-influenced of the NemoClaw injection points even though the CVSS vector is scored local. Operators who have not enabled the Telegram bridge are not exposed by this specific issue, but it ships in the same affected builds as the other NemoClaw command-injection flaws, so the update is the same one.

Who can reach it

A local, low-privileged actor able to influence what the Telegram bridge processes (CVSS AV:L, PR:L). Authentication required. Only relevant on deployments where the Telegram bridge is configured.

What to do

Update NemoClaw from the NVIDIA/NemoClaw GitHub repo - versions 0 through 0.0.25 are affected per bulletin 5872, with the fixed version for this CVE given in that bulletin's Security Updates table. If the Telegram bridge is not in use, disabling or not configuring it removes exposure to this issue without a restart, but the sibling injection flaws in the same builds still warrant the update.

References

Related entries

All AI/ML frameworks & serving entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.