Tools AI Risk Radar ai-incident-0030
Incident record
A pair of critical escapes in OpenShell, the sandbox NVIDIA built to contain AI agents
- Severity
- Critical
- Status
- Patched
- Type
- Agent Hijack
- Target
- NVIDIA OpenShell, the sandbox NemoClaw runs agents inside
- Actor
- researcher
- CVE
- CVE-2026-65093
What happened
Two flaws in OpenShell, both rated 9.9 by NVIDIA, break out of the fence the product exists to hold. CVE-2026-65093 is an uncontrolled search path that escapes the sandbox outright; CVE-2026-65083 is an incomplete denylist in the sandbox provisioning API. NVIDIA lists code execution, privilege escalation, data tampering and information disclosure as the impact of both, and denial of service for the second.
OpenShell is what NemoClaw runs an agent inside, fencing off the file system, the network and processes. Versions up to 0.0.33 on every platform are affected and 0.0.34 carries the fix. The same bulletin adds CVE-2026-65091, OS command injection through a malicious gateway at 8.8, and CVE-2026-65092, a path traversal that bypasses the layer-7 REST network policy at 8.5. NVIDIA credits Leo Lin with three of those four and yongzhi with the denylist bypass, says the whole set was found externally, and claims no exploitation.
Sources
- NVIDIA product security: bulletin 5872, NemoClaw and OpenShell (25 August 2026)github.com/NVIDIA/product-security/tree/main/2026/5872
One record from the AI Risk Radar, maintained by the Security Desk. Data: CSV · JSON ·RSS · CC BY 4.0 with attribution to YFarmX.Tracker updated · 18 September 2026