Description
NVIDIA NemoClaw for Linux contains a vulnerability in its installation process, where an attacker could cause execution of untrusted code. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, information disclosure, and denial of service.
Published: 2026-08-25
Score: 8.1 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

During the NemoClaw installation process the vendor fails to isolate untrusted code, allowing an attacker to execute arbitrary binaries. The vulnerability can culminate in code execution, elevation of privileges, alteration of data, disclosure of sensitive information, and a denial‑of‑service condition. The weakness aligns with CWE‑494, where a program reads or executes code from an untrusted source without sufficient validation.

Affected Systems

The affected product is NVIDIA NemoClaw for Linux. No specific version information is supplied in the advisory; all releases that use the vulnerable installation mechanism are potentially impacted.

Risk and Exploitability

The CVSS score of 8.1 signals high severity. EPSS information is unavailable, so the current exploitation probability cannot be determined. The vulnerability is not listed in CISA KEV, and there is no public exploit code reported. The likely attack vector is during installation, which could be local or remote if an attacker controls the installation media. The combination of high severity and the need for local installation access means that any user with the ability to install software is at risk.

Generated by OpenCVE AI on August 25, 2026 at 21:37 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest NemoClaw release that contains the installation fix.
  • Verify the installer’s SHA256 checksum against the vendor‑provided value before executing it.
  • Restrict NemoClaw installation privileges to trusted administrators only.

Generated by OpenCVE AI on August 25, 2026 at 21:37 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 25 Aug 2026 22:30:00 +0000

Type Values Removed Values Added
First Time appeared Nvidia
Nvidia nemoclaw
Vendors & Products Nvidia
Nvidia nemoclaw

Tue, 25 Aug 2026 22:00:00 +0000

Type Values Removed Values Added
Title Untrusted Code Execution During NemoClaw Installation

Tue, 25 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Description NVIDIA NemoClaw for Linux contains a vulnerability in its installation process, where an attacker could cause execution of untrusted code. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, information disclosure, and denial of service.
Weaknesses CWE-494
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: nvidia

Published:

Updated: 2026-08-25T20:15:26.001Z

Reserved: 2026-07-21T17:05:36.472Z

Link: CVE-2026-65081

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-25T21:17:27.793

Modified: 2026-08-25T21:17:27.793

Link: CVE-2026-65081

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-25T22:15:04Z

Weaknesses
  • CWE-494

    Download of Code Without Integrity Check