Description
NVIDIA NemoClaw for Linux contains a vulnerability in its installation process, where an attacker could cause execution of untrusted code. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, information disclosure, and denial of service.
Published: 2026-08-25
Score: 8.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Code Execution and Privilege Escalation
Action: Patch Immediately
AI Analysis

Impact

During the NemoClaw installation process the vendor fails to isolate untrusted code, allowing an attacker to execute arbitrary binaries. The vulnerability can culminate in code execution, elevation of privileges, alteration of data, disclosure of sensitive information, and a denial‑of‑service condition. The weakness aligns with CWE‑494, where a program reads or executes code from an untrusted source without sufficient validation.

Affected Systems

The affected product is NVIDIA NemoClaw for Linux. No specific version information is supplied in the advisory; all releases that use the vulnerable installation mechanism are potentially impacted.

Risk and Exploitability

The CVSS score of 8.1 signals high severity. EPSS information is unavailable, so the current exploitation probability cannot be determined. The vulnerability is not listed in CISA KEV, and there is no public exploit code reported. The likely attack vector is during installation, which could be local or remote if an attacker controls the installation media. The combination of high severity and the need for local installation access means that any user with the ability to install software is at risk.

Generated by OpenCVE AI on August 25, 2026 at 21:37 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest NemoClaw release that contains the installation fix.
  • Verify the installer’s SHA256 checksum against the vendor‑provided value before executing it.
  • Restrict NemoClaw installation privileges to trusted administrators only.

Generated by OpenCVE AI on August 25, 2026 at 21:37 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 01 Sep 2026 22:00:00 +0000

Type Values Removed Values Added
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:a:nvidia:nemoclaw:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel

Wed, 26 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 25 Aug 2026 22:30:00 +0000

Type Values Removed Values Added
First Time appeared Nvidia
Nvidia nemoclaw
Vendors & Products Nvidia
Nvidia nemoclaw

Tue, 25 Aug 2026 22:00:00 +0000

Type Values Removed Values Added
Title Untrusted Code Execution During NemoClaw Installation

Tue, 25 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Description NVIDIA NemoClaw for Linux contains a vulnerability in its installation process, where an attacker could cause execution of untrusted code. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, information disclosure, and denial of service.
Weaknesses CWE-494
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Linux Linux Kernel
Nvidia Nemoclaw
cve-icon MITRE

Status: PUBLISHED

Assigner: nvidia

Published:

Updated: 2026-08-26T18:46:52.672Z

Reserved: 2026-07-21T17:05:36.472Z

Link: CVE-2026-65081

cve-icon Vulnrichment

Updated: 2026-08-26T18:46:47.567Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-25T21:17:27.793

Modified: 2026-09-01T18:59:24.963

Link: CVE-2026-65081

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-25T22:15:04Z

Weaknesses
  • CWE-494

    Download of Code Without Integrity Check