NVIDIA NemoClaw
Open-source AI
Impact proxy: Data confidentiality · Application integrity · Platform resilience · Transaction and trust integrity
CompletedProject
Project GlassBreak is FailSafe's public-good responsible disclosure program. We identify vulnerabilities across open-source repositories and public-facing systems, report them responsibly, and contribute fixes upstream where possible.
Our aim is straightforward: make the software everyone builds on safer, protect the organizations people rely on, and give back to the community.
Our approach
GlassBreak gives back to the open-source community through responsible reports and upstream fixes. The program also covers coordinated disclosures made privately to organizations.
We coordinate timing with maintainers and affected teams. Private disclosures receive public-safe summaries; open-source entries are grouped into simple program-level statuses, with linked upstream records serving as the detailed source of truth.
Disclosure process
A remediation-first process from discovery to a safe public record.
We identify security weaknesses in open-source repositories and public-facing systems.
We notify the security or engineering team directly with full details.
We support maintainers and affected teams as they validate and fix the issue.
We record a public-safe summary or link the upstream contribution when appropriate.
GlassBreak registry
Summaries are deliberately limited to information that cannot be used to reproduce or exploit a finding.
| Organization | Sector | Findings | Severity | Finding types | Impact proxy | Status |
|---|---|---|---|---|---|---|
| NVIDIA NemoClaw | Open-source AI | 3 | Medium 3 | File and path safety · Object integrity · Network request security | Data confidentiality · Application integrity · Platform resilience · Transaction and trust integrity | Completed |
| Grab KartaView | Open-source mapping | 13 | Critical 5High 8 | API access control · Data protection · Cloud and network security · Identity and session security | Data confidentiality · Account and access security · Application integrity · Platform resilience | In progress |
| IBM MCP Context Forge | AI infrastructure | 1 | High 1 | Secrets policy | Account and access security | In progress |
| Bristol Myers Squibb | Pharmaceuticals | 1 | Critical 1 | Infrastructure and dependency security | Platform resilience | Disclosed |
| MUFG | Banking | 3 | High 2Medium 1 | Identity and access · Application logic | Account and access security · Application integrity | Disclosed |
| Deutsche Bank | Banking | 2 | Critical 1High 1 | Data protection · Infrastructure security | Data confidentiality · Platform resilience | Disclosed |
| Zurich Insurance | Insurance | 1 | High 1 | Identity and access | Account and access security | Disclosed |
| Swiss Re | Reinsurance | 2 | High 2 | Application data protection · Identity security | Data confidentiality · Account and access security · Application integrity | Remediated |
| Liberty Mutual | Insurance | 1 | High 1 | Identity and web security | Account and access security · Application integrity | Disclosed |
| ICICI Lombard | Insurance | 5 | Critical 1High 4 | Data protection · Secrets and access control | Data confidentiality · Account and access security | Remediated |
| HDFC ERGO | Insurance | 5 | Critical 4High 1 | Data protection · API and infrastructure security | Data confidentiality · Application integrity · Platform resilience | Disclosed |
| Sun Pharma | Pharmaceuticals | 3 | Critical 1High 2 | Secrets management · Data protection | Data confidentiality · Account and access security | Disclosed |
| Dr. Reddy's | Pharmaceuticals | 2 | Critical 1High 1 | Data access control · Web application security | Data confidentiality · Account and access security · Application integrity | Disclosed |
| Vercel | Developer infrastructure | 1 | High 1 | Request routing · Execution safeguards | Application integrity | In progress |
| Supabase MCP | Developer infrastructure | 1 | Medium 1 | Resource limits · Availability | Platform resilience · Service resilience | In progress |
Open-source AI
Impact proxy: Data confidentiality · Application integrity · Platform resilience · Transaction and trust integrity
CompletedOpen-source mapping
Impact proxy: Data confidentiality · Account and access security · Application integrity · Platform resilience
In progressAI infrastructure
Impact proxy: Account and access security
In progressPharmaceuticals
Impact proxy: Platform resilience
DisclosedBanking
Impact proxy: Account and access security · Application integrity
DisclosedBanking
Impact proxy: Data confidentiality · Platform resilience
DisclosedInsurance
Impact proxy: Account and access security
DisclosedReinsurance
Impact proxy: Data confidentiality · Account and access security · Application integrity
RemediatedInsurance
Impact proxy: Account and access security · Application integrity
DisclosedInsurance
Impact proxy: Data confidentiality · Account and access security
RemediatedInsurance
Impact proxy: Data confidentiality · Application integrity · Platform resilience
DisclosedPharmaceuticals
Impact proxy: Data confidentiality · Account and access security
DisclosedPharmaceuticals
Impact proxy: Data confidentiality · Account and access security · Application integrity
DisclosedDeveloper infrastructure
Impact proxy: Application integrity
In progressDeveloper infrastructure
Impact proxy: Platform resilience · Service resilience
In progressIf your organization or project has received a GlassBreak disclosure and you'd like to coordinate remediation, update a listing, or request removal, contact our security team.
[email protected]Questions & answers
How GlassBreak coordinates, publishes, and maintains responsible disclosures.
Project GlassBreak is FailSafe's public-good responsible-disclosure program for open-source repositories and public-facing systems.
GlassBreak identifies a security weakness, notifies the relevant maintainers or security team privately, supports remediation, and publishes a safe record when appropriate.
No. Private disclosure summaries deliberately omit affected systems, exploit paths, personal data types, credentials, and other details that could increase risk.
The registry uses four program-level statuses: Remediated for confirmed fixes, Completed for concluded upstream work, In progress for active upstream review, and Disclosed when a safe public record exists without a confirmed remediation outcome.
Contact [email protected] to coordinate remediation, correct a listing, or request removal from the public registry.