Junglewise Threat Intelligence

CVE-2026-65089: NVIDIA NemoClaw OS command injection in status and logs plugin

CVE-2026-65089 · Severity: high · CVSS 7.8 · Published 2026-08-25

Technologies: Nvidia Nemoclaw, Linux Kernel. Vendors: Nvidia, Linux.

Executive brief

NVIDIA NemoClaw is a Linux-based application used for system management and monitoring. The status and logs plugin commands are vulnerable to OS command injection, allowing an attacker to execute arbitrary system commands. A successful exploit could result in unauthorized code execution, data theft or corruption, information disclosure, and service disruption.

Technical details

The vulnerability is an OS command injection flaw in the status and logs plugin commands of NVIDIA NemoClaw for Linux. The root cause appears to be insufficient input validation or sanitization of user-supplied data passed to system commands. An attacker can inject arbitrary OS commands through the affected plugin, potentially achieving code execution with the privileges of the NemoClaw process. The vulnerability is remotely exploitable and may require the attacker to have access to trigger the plugin commands. No patch status is explicitly mentioned in the advisory.

Affected products

  • NVIDIA NemoClaw <UNKNOWN>

Timeline

  • 2026-08-25: disclosed

References

Related threats