Description
NVIDIA NemoClaw for Linux contains a vulnerability in the Telegram bridge component, where an attacker could cause an OS command injection. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, information disclosure, and data tampering.
Published: 2026-08-25
Score: 7.8 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

NVIDIA NemoClaw for Linux contains a command injection vulnerability in its Telegram bridge component. An attacker capable of injecting operating system commands can achieve remote code execution, privilege escalation, information disclosure, and data tampering. This weakness is classified as CWE-78 (OS Command Injection).

Affected Systems

The affected product is NVIDIA NemoClaw running on Linux. No specific affected version range is listed in the vendor data, so administrators should treat all current installations as potentially vulnerable until an official patch is released.

Risk and Exploitability

The CVSS score of 7.8 indicates a high severity vulnerability, while the EPSS score is not available, making the exact likelihood of exploitation unclear. The vulnerability is not yet listed in the CISA KEV catalog. Based on the description, it is inferred that an attacker could exploit this weakness remotely via the Telegram bridge, possibly by sending specially crafted messages that trigger command execution. Because no official workaround is provided, administrators should prepare for a high-risk scenario until the vendor releases a fix.

Generated by OpenCVE AI on August 25, 2026 at 22:03 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update NVIDIA NemoClaw to the latest version that includes the fix for the Telegram bridge command injection.
  • If a patch is not yet available, disable or block the Telegram bridge component to eliminate the attack surface.
  • Implement strict input validation or sanitization on all data received by the Telegram bridge to prevent arbitrary command injection.
  • Monitor system logs for unexpected command execution and investigate any anomalies promptly.

Generated by OpenCVE AI on August 25, 2026 at 22:03 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 25 Aug 2026 22:30:00 +0000

Type Values Removed Values Added
Title NVIDIA NemoClaw Linux Telegram Bridge OS Command Injection

Tue, 25 Aug 2026 21:45:00 +0000

Type Values Removed Values Added
First Time appeared Nvidia
Nvidia nemoclaw
Vendors & Products Nvidia
Nvidia nemoclaw

Tue, 25 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Description NVIDIA NemoClaw for Linux contains a vulnerability in the Telegram bridge component, where an attacker could cause an OS command injection. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, information disclosure, and data tampering.
Weaknesses CWE-78
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: nvidia

Published:

Updated: 2026-08-25T20:15:20.120Z

Reserved: 2026-07-21T17:05:44.174Z

Link: CVE-2026-65096

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-25T21:17:29.433

Modified: 2026-08-25T21:17:29.433

Link: CVE-2026-65096

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-25T22:15:04Z

Weaknesses
  • CWE-78

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')