Database/AI/ML frameworks & serving
NVIDIA NemoClaw: OS command injection in the Telegram bridge component
Impact
The Telegram bridge in NemoClaw passes input into an OS command without adequate sanitisation, which NVIDIA says may lead to code execution, privilege escalation, information disclosure and data tampering. The bridge is a notification path, so the input it handles arrives from outside the node - that makes it the most externally-influenced of the NemoClaw injection points even though the CVSS vector is scored local. Operators who have not enabled the Telegram bridge are not exposed by this specific issue, but it ships in the same affected builds as the other NemoClaw command-injection flaws, so the update is the same one.
Who can reach it
A local, low-privileged actor able to influence what the Telegram bridge processes (CVSS AV:L, PR:L). Authentication required. Only relevant on deployments where the Telegram bridge is configured.
What to do
Update NemoClaw from the NVIDIA/NemoClaw GitHub repo - versions 0 through 0.0.25 are affected per bulletin 5872, with the fixed version for this CVE given in that bulletin's Security Updates table. If the Telegram bridge is not in use, disabling or not configuring it removes exposure to this issue without a restart, but the sibling injection flaws in the same builds still warrant the update.
References
Related entries
- NVIDIA NemoClaw: OS command injection through the command-line interfaceCVE-2026-65099 · NVIDIA NemoClaw for Linux (command-line interface)High
- PyTorch (flatbuffer model parsing, torch::load / parse_and_initialize_mobile_module): MALICIOUS MODEL FILE TO MEMORYNCVD-2025-019-pytorch-flatbuffer-model-parsing · PyTorch (flatbuffer model parsing, torch::load / parse_and_initialize_mobile_module)High
- LangChain (Web Research Retriever): SSRFCVE-2024-3095 · LangChain (Web Research Retriever)High
- SitemapLoader: nested sitemap entries skip restrict_to_same_domain, giving readable SSRFCVE-2026-72848 · langchain-community SitemapLoader (nested sitemap index entries)High
- Headroom LLM proxy: client-chosen upstream base URL enables SSRF and leaks the Authorization headerCVE-2026-77775 · Headroom LLM proxy (x-headroom-base-url upstream selection)High
- JupyterLab: XSS via untrusted notebook contentCVE-2024-43805 · JupyterLabHigh
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.