Junglewise Threat Intelligence

CVE-2026-65085: NVIDIA OpenShell improper encoding or escaping in inference proxy

CVE-2026-65085 · Severity: medium · CVSS 5.2 · Published 2026-08-25

Technologies: Linux Kernel. Vendors: Nvidia, Linux.

Executive brief

NVIDIA OpenShell for Linux is a tool used to interact with AI inference services. A vulnerability in its inference proxy component allows attackers to improperly encode or escape output, potentially exposing sensitive information or altering data. This could lead to unauthorized access to confidential model outputs or system information.

Technical details

The vulnerability is rooted in improper encoding or escaping of output in the inference proxy component of NVIDIA OpenShell for Linux. The flaw allows an attacker to craft requests that result in unescaped or improperly encoded responses, potentially leading to information disclosure through output manipulation or data tampering. The attack vector appears to be network-reachable, though specific authentication requirements are not documented. Successful exploitation could expose sensitive inference data or allow modification of proxy responses.

Affected products

  • NVIDIA OpenShell <UNKNOWN>

Timeline

  • 2026-08-25: disclosed

References

Related threats