Impact
NVIDIA NemoClaw for Linux contains a command injection vulnerability in its Telegram bridge component. An attacker capable of injecting operating system commands can achieve remote code execution, privilege escalation, information disclosure, and data tampering. This weakness is classified as CWE-78 (OS Command Injection).
Affected Systems
The affected product is NVIDIA NemoClaw running on Linux. No specific affected version range is listed in the vendor data, so administrators should treat all current installations as potentially vulnerable until an official patch is released.
Risk and Exploitability
The CVSS score of 7.8 indicates a high severity vulnerability, while the EPSS score is not available, making the exact likelihood of exploitation unclear. The vulnerability is not yet listed in the CISA KEV catalog. Based on the description, it is inferred that an attacker could exploit this weakness remotely via the Telegram bridge, possibly by sending specially crafted messages that trigger command execution. Because no official workaround is provided, administrators should prepare for a high-risk scenario until the vendor releases a fix.
OpenCVE Enrichment