Impact
NVIDIA OpenShell for Linux contains an OS command injection flaw in its sandbox exec handler. An attacker who can trigger the vulnerable handler may execute arbitrary system commands, which can lead to remote code execution, exposure of confidential data, and modification of stored information. The weakness is a classic OS command injection (CWE-78).
Affected Systems
The vulnerability affects NVIDIA OpenShell on Linux platforms. No specific product versions are listed, so all current installations of this sandbox component are potentially impacted.
Risk and Exploitability
The CVSS score of 6.8 indicates a moderate risk profile. The EPSS score of 1% indicates a low but non-zero likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. Based on the description, the attack vector likely requires the attacker to invoke the sandbox exec handler, suggesting local or privileged access is needed, though the exact prerequisites are not detailed in the advisory.
OpenCVE Enrichment