Description
NVIDIA NemoClaw for Linux contains a vulnerability in its installation scripts, where an attacker could cause a download of code without integrity check. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, information disclosure, and data tampering.
Published: 2026-08-25
Score: 7.5 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

NVIDIA NemoClaw for Linux includes a flaw in its installation scripts where downloaded code is not verified for integrity. An attacker can use this weakness to have the installer download malicious code, leading to arbitrary code execution, privilege escalation, and potential information disclosure or data tampering. The underlying weakness corresponds to CWE-494, reflecting the absence of a proper integrity check. The likely attack vector is through manipulation of the installation environment or the source from which the installer retrieves its components, which is inferred from the description of missing integrity verification during code download.

Affected Systems

The affected product is NVIDIA NemoClaw on Linux platforms. Specific version information is not provided in the available data, so any publicly released version that includes the vulnerable installation scripts may be impacted.

Risk and Exploitability

The CVSS score for this vulnerability is 7.5, indicating a high severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. The risk is elevated because an attacker who can modify the installation script, the repository source, or coerce a user to run a compromised installer can execute arbitrary code and elevate privileges. Exploitation would typically require access to the installation environment and the ability to direct the installer to download unverified code.

Generated by OpenCVE AI on August 25, 2026 at 22:02 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the vendor’s patch or update to a version of NemoClaw that includes the fixed installation script
  • Verify the integrity of installation scripts by checking digital signatures or cryptographic hash values before execution
  • Restrict permissions for the installation process and audit downloaded artifacts to ensure only trusted code is executed

Generated by OpenCVE AI on August 25, 2026 at 22:02 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 25 Aug 2026 22:30:00 +0000

Type Values Removed Values Added
Title Unverified Download in NVIDIA NemoClaw Installation Scripts Enables Code Execution

Tue, 25 Aug 2026 22:15:00 +0000

Type Values Removed Values Added
First Time appeared Nvidia
Nvidia nemoclaw
Vendors & Products Nvidia
Nvidia nemoclaw

Tue, 25 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Description NVIDIA NemoClaw for Linux contains a vulnerability in its installation scripts, where an attacker could cause a download of code without integrity check. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, information disclosure, and data tampering.
Weaknesses CWE-494
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: nvidia

Published:

Updated: 2026-08-25T20:15:21.152Z

Reserved: 2026-07-21T17:05:44.174Z

Link: CVE-2026-65097

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-25T21:17:29.560

Modified: 2026-08-25T21:17:29.560

Link: CVE-2026-65097

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-25T22:15:04Z

Weaknesses
  • CWE-494

    Download of Code Without Integrity Check