Description
NVIDIA NemoClaw for Linux contains a vulnerability in its migration command, where a local attacker could cause code injection. A successful exploit of this vulnerability might lead to code execution, data tampering, information disclosure, and denial of service.
Published: 2026-08-25
Score: 7 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

NVIDIA NemoClaw for Linux includes a flaw in its migration command that allows a local attacker to inject and execute arbitrary code. This code injection vulnerability can result in code execution, data tampering, information disclosure, and denial of service. The weakness corresponds to CWE-94, an improper control of code generation.

Affected Systems

The affected product is NVIDIA NemoClaw running on Linux. No specific version details were provided, but any installation of the product is potentially compromised until a patched version is applied.

Risk and Exploitability

The CVSS score of 7 indicates medium severity for local exploitation. EPSS is not available, and the vulnerability is not listed in KEV. The likely attack vector is from a local user with privileges to run the migration command, as the description specifies a local attacker. Because the issue permits arbitrary code execution, the potential impact is significant should an attacker gain appropriate access.

Generated by OpenCVE AI on August 25, 2026 at 21:59 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest NVIDIA NemoClaw release or patch that fixes the migration command code injection bug.
  • Restrict the migration command so that only authorized users with minimal privileges can execute it.
  • If a patch is not yet available, disable or quarantine the migration feature until a fix is released.

Generated by OpenCVE AI on August 25, 2026 at 21:59 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 25 Aug 2026 22:15:00 +0000

Type Values Removed Values Added
Title Code Injection Vulnerability in NVIDIA NemoClaw’s Migration Command
First Time appeared Nvidia
Nvidia nemoclaw
Vendors & Products Nvidia
Nvidia nemoclaw

Tue, 25 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Description NVIDIA NemoClaw for Linux contains a vulnerability in its migration command, where a local attacker could cause code injection. A successful exploit of this vulnerability might lead to code execution, data tampering, information disclosure, and denial of service.
Weaknesses CWE-94
References
Metrics cvssV3_1

{'score': 7, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: nvidia

Published:

Updated: 2026-08-25T20:15:26.970Z

Reserved: 2026-07-21T17:05:36.472Z

Link: CVE-2026-65082

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-25T21:17:27.923

Modified: 2026-08-25T21:17:27.923

Link: CVE-2026-65082

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-25T22:00:13Z

Weaknesses
  • CWE-94

    Improper Control of Generation of Code ('Code Injection')