Junglewise Threat Intelligence

CVE-2026-65088: NVIDIA NemoClaw information disclosure via process invocation

CVE-2026-65088 · Severity: medium · CVSS 5.5 · Published 2026-08-25

Technologies: Nvidia Nemoclaw, Linux Kernel. Vendors: Nvidia, Linux.

Executive brief

NVIDIA NemoClaw is a tool used for processing and inference tasks. A vulnerability in the product allows an attacker to invoke processes while exposing sensitive information in plain view, potentially leading to unauthorized disclosure of confidential data such as API keys, credentials, or other sensitive parameters.

Technical details

The vulnerability is an information disclosure issue in NVIDIA NemoClaw where sensitive information is visible during process invocation. An attacker can leverage this to extract sensitive data that is inadvertently exposed through process parameters, environment variables, or command-line arguments. The attack vector is not fully detailed in the advisory, but the medium CVSS score and information disclosure impact suggest the vulnerability requires some level of access or observation capability. The exact affected component and versions are not specified in the provided content.

Affected products

  • NVIDIA NemoClaw <UNKNOWN>

Timeline

  • 2026-08-25: disclosed

References

Related threats