TL;DR
NVIDIA released a software update for NemoClaw and OpenShell. It fixes 20 vulnerabilities, including two critical flaws scored CVSS 9.9. The worst, CVE-2026-65093, allows a sandbox escape leading to code execution. Update from the official GitHub repos now.
- Total: 18 CVEs
- Severity: 2 Critical · 12 High · 4 Medium
- Actively exploited: None confirmed
- Highest severity: 9.9 (Critical · CVSSv3) — CVE-2026-65093
- Action: Apply the latest security updates now
Notable CVEs
| CVE | CVSS (CVSSv3) | Type | Fixed in | Status |
|---|---|---|---|---|
| CVE-2026-65093 | 9.9 | CWE-427 | — | Not exploited |
| CVE-2026-65083 | 9.9 | CWE-184 | — | Not exploited |
| CVE-2026-65091 | 8.8 | CWE-78 | — | Not exploited |
| CVE-2026-65092 | 8.5 | CWE-22 | — | Not exploited |
| CVE-2026-65098 | 8.1 | CWE-1390 | — | Not exploited |
| CVE-2026-65081 | 8.1 | CWE-494 | — | Not exploited |
| CVE-2026-65084 | 8.1 | CWE-295 | — | Not exploited |
| CVE-2026-65105 | 8.1 | CWE-306 | — | Not exploited |
Why These NVIDIA Vulnerabilities Matter
NemoClaw and OpenShell support NVIDIA’s AI tooling on Linux. Many teams run them close to sensitive models and data. This NVIDIA vulnerability set therefore reaches high-value systems.
Two flaws hit the maximum-adjacent 9.9 score. Because they enable code execution, the stakes are high. NVIDIA delivers fixes through its GitHub repositories rather than a driver installer.
How the Attacks Work
Critical Sandbox Flaws
The top bug, CVE-2026-65093, is a sandbox escape in OpenShell for Linux. NVIDIA warns a successful exploit might lead to code execution, escalation of privileges, data tampering, and information disclosure.
The second critical, CVE-2026-65083, stems from an incomplete list of disallowed inputs in the sandbox provisioning API.
Command Injection and Weak Authentication
Many High-severity bugs involve OS command injection. For example, CVE-2026-65091 lets a malicious gateway inject commands across all OpenShell platforms. Several NemoClaw components share this weakness, including its Telegram bridge and command-line interface.
Other flaws weaken trust checks. CVE-2026-65098 involves weak authentication in a remote-access helper. CVE-2026-65105 may let a remote attacker reach the inference service without authentication.
Is It Being Exploited?
No exploitation in the wild has been confirmed. NVIDIA reports no active attacks. Likewise, no public proof-of-concept exists yet.
Affected Versions
OpenShell versions 0 through 0.0.33 are affected on all platforms. NemoClaw for Linux is affected across several component versions, up to builds like 0.0.25, 0.0.21, and 0.0.17.
Patch and Mitigation Steps
Update OpenShell to v0.0.34 from the official repo. For NemoClaw, clone or pull the fixed component builds listed by NVIDIA. The full table appears in the NVIDIA security bulletin. Since fixes ship through GitHub, verify you track the correct NVIDIA/NemoClaw and NVIDIA/OpenShell repositories.
Support Our Threat Intelligence
Find our zero-day alerts and CVE reports helpful? Support our work today and unlock a 100% ad-free reading experience!