Impact
An OS command injection flaw exists in the status and logs plugin commands of NVIDIA NemoClaw for Linux. An attacker able to supply crafted input to these commands can cause arbitrary shell commands to run on the host, leading to code execution, data tampering, information disclosure, and denial of service. The weakness is an example of CWE‑78: Improper Neutralization of Special Elements used in an OS Command.
Affected Systems
The vulnerability affects NVIDIA NemoClaw for Linux. Specific affected releases are not listed in the advisory; therefore, the scope of vulnerability remains uncertain. Organizations should verify whether their current deployments are affected and apply the vendor patch when available.
Risk and Exploitability
The CVSS score of 7.8 indicates high severity. The EPSS score is not available, but the lack of a KEV listing suggests no confirmed exploits yet. The likely attack vector is through privileged access to the plugin interface; a local or potentially remote attacker with sufficient privileges could trigger the command injection. Given the high severity and the potential impact, the risk remains significant until mitigated.
OpenCVE Enrichment