Impact
NVIDIA NemoClaw for Linux includes a flaw in its command-line interface that allows an attacker to inject arbitrary operating-system commands. This command-line injection can be used to execute malicious code, tamper with data, disclose sensitive information, or cause a denial of service on the affected system.
Affected Systems
The vulnerability affects all installations of NVIDIA NemoClaw running on Linux. No specific version range is provided by the vendor, so all releases should be considered potentially impacted until a patch is released.
Risk and Exploitability
The CVSS score of 7.8 indicates a high severity level. The EPSS score is not available, but the lack of a CISA KEV listing suggests no widely known exploitation yet. The likely attack vector is local to the machine with access to the command-line interface; however, the ability to execute arbitrary OS commands implies a high impact if the attacker can access the interface. Exploitation would require the attacker to run the vulnerable command with the appropriate rights, making privilege escalation a prerequisite in many scenarios.
OpenCVE Enrichment