Description
NVIDIA NemoClaw for Linux contains a vulnerability in its command-line interface, where an attacker could cause OS command injection. A successful exploit of this vulnerability might lead to code execution, data tampering, information disclosure, and denial of service.
Published: 2026-08-25
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Potential Code Execution via Command Injection
Action: Apply Patch
AI Analysis

Impact

NVIDIA NemoClaw for Linux includes a flaw in its command-line interface that allows an attacker to inject arbitrary operating-system commands. This command-line injection can be used to execute malicious code, tamper with data, disclose sensitive information, or cause a denial of service on the affected system.

Affected Systems

The vulnerability affects all installations of NVIDIA NemoClaw running on Linux. No specific version range is provided by the vendor, so all releases should be considered potentially impacted until a patch is released.

Risk and Exploitability

The CVSS score of 7.8 indicates a high severity level. The EPSS score is not available, but the lack of a CISA KEV listing suggests no widely known exploitation yet. The likely attack vector is local to the machine with access to the command-line interface; however, the ability to execute arbitrary OS commands implies a high impact if the attacker can access the interface. Exploitation would require the attacker to run the vulnerable command with the appropriate rights, making privilege escalation a prerequisite in many scenarios.

Generated by OpenCVE AI on August 25, 2026 at 22:01 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest NVIDIA NemoClaw update once it is released.
  • Restrict access to the NemoClaw command-line interface by controlling OS user permissions.
  • If the command-line interface cannot be removed, validate and sanitize any user-supplied input before executing system commands.

Generated by OpenCVE AI on August 25, 2026 at 22:01 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 01 Sep 2026 22:00:00 +0000

Type Values Removed Values Added
First Time appeared Linux
Linux linux Kernel
CPEs cpe:2.3:a:nvidia:nemoclaw:0.0.1:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
Vendors & Products Linux
Linux linux Kernel

Wed, 26 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 25 Aug 2026 22:30:00 +0000

Type Values Removed Values Added
Title Linux Command Injection in NVIDIA NemoClaw Command-Line Interface

Tue, 25 Aug 2026 22:00:00 +0000

Type Values Removed Values Added
First Time appeared Nvidia
Nvidia nemoclaw
Vendors & Products Nvidia
Nvidia nemoclaw

Tue, 25 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Description NVIDIA NemoClaw for Linux contains a vulnerability in its command-line interface, where an attacker could cause OS command injection. A successful exploit of this vulnerability might lead to code execution, data tampering, information disclosure, and denial of service.
Weaknesses CWE-78
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Linux Linux Kernel
Nvidia Nemoclaw
cve-icon MITRE

Status: PUBLISHED

Assigner: nvidia

Published:

Updated: 2026-08-26T14:41:05.180Z

Reserved: 2026-07-21T17:05:44.174Z

Link: CVE-2026-65099

cve-icon Vulnrichment

Updated: 2026-08-26T14:40:57.523Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-25T21:17:29.817

Modified: 2026-09-01T18:40:29.450

Link: CVE-2026-65099

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-25T22:15:04Z

Weaknesses
  • CWE-78

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')