Description
NVIDIA NemoClaw for Linux contains a vulnerability in its command-line interface, where an attacker could cause OS command injection. A successful exploit of this vulnerability might lead to code execution, data tampering, information disclosure, and denial of service.
Published: 2026-08-25
Score: 7.8 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

NVIDIA NemoClaw for Linux includes a flaw in its command-line interface that allows an attacker to inject arbitrary operating-system commands. This command-line injection can be used to execute malicious code, tamper with data, disclose sensitive information, or cause a denial of service on the affected system.

Affected Systems

The vulnerability affects all installations of NVIDIA NemoClaw running on Linux. No specific version range is provided by the vendor, so all releases should be considered potentially impacted until a patch is released.

Risk and Exploitability

The CVSS score of 7.8 indicates a high severity level. The EPSS score is not available, but the lack of a CISA KEV listing suggests no widely known exploitation yet. The likely attack vector is local to the machine with access to the command-line interface; however, the ability to execute arbitrary OS commands implies a high impact if the attacker can access the interface. Exploitation would require the attacker to run the vulnerable command with the appropriate rights, making privilege escalation a prerequisite in many scenarios.

Generated by OpenCVE AI on August 25, 2026 at 22:01 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest NVIDIA NemoClaw update once it is released.
  • Restrict access to the NemoClaw command-line interface by controlling OS user permissions.
  • If the command-line interface cannot be removed, validate and sanitize any user-supplied input before executing system commands.

Generated by OpenCVE AI on August 25, 2026 at 22:01 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 25 Aug 2026 22:30:00 +0000

Type Values Removed Values Added
Title Linux Command Injection in NVIDIA NemoClaw Command-Line Interface

Tue, 25 Aug 2026 22:00:00 +0000

Type Values Removed Values Added
First Time appeared Nvidia
Nvidia nemoclaw
Vendors & Products Nvidia
Nvidia nemoclaw

Tue, 25 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Description NVIDIA NemoClaw for Linux contains a vulnerability in its command-line interface, where an attacker could cause OS command injection. A successful exploit of this vulnerability might lead to code execution, data tampering, information disclosure, and denial of service.
Weaknesses CWE-78
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: nvidia

Published:

Updated: 2026-08-25T20:15:23.086Z

Reserved: 2026-07-21T17:05:44.174Z

Link: CVE-2026-65099

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-25T21:17:29.817

Modified: 2026-08-25T21:17:29.817

Link: CVE-2026-65099

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-25T22:15:04Z

Weaknesses
  • CWE-78

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')