Impact
OpenShell for Linux contains a sandbox escape vulnerability that can grant an attacker arbitrary code execution beyond the intended confinement. This flaw allows elevation of privileges, data tampering, and exposure of sensitive information, aligning with the Path Manipulation weakness identified as CWE-427.
Affected Systems
The affected product is NVIDIA OpenShell running on Linux systems. The specific version information is not disclosed in the public data, implying that all current releases may remain vulnerable until a vendor update is issued.
Risk and Exploitability
The CVSS score is 9.9, indicating a critical issue. The EPSS score is not available, so the likelihood of exploitation is uncertain; however, the high severity and the potential for code execution and privilege escalation make it a top priority for remediation. The vulnerability is not listed in the CISA KEV catalog, but the impact warrants rapid action.
OpenCVE Enrichment