Executive brief
NVIDIA NemoClaw is a tool used for processing and inference tasks. A vulnerability in the product allows an attacker to invoke processes while exposing sensitive information in plain view, potentially leading to unauthorized disclosure of confidential data such as API keys, credentials, or other sensitive parameters.
Technical details
The vulnerability is an information disclosure issue in NVIDIA NemoClaw where sensitive information is visible during process invocation. An attacker can leverage this to extract sensitive data that is inadvertently exposed through process parameters, environment variables, or command-line arguments. The attack vector is not fully detailed in the advisory, but the medium CVSS score and information disclosure impact suggest the vulnerability requires some level of access or observation capability. The exact affected component and versions are not specified in the provided content.
Affected products
- NVIDIA NemoClaw <UNKNOWN>
Timeline
- 2026-08-25: disclosed