Executive brief
NVIDIA NemoClaw for Linux includes a network management component (NIM) that is vulnerable to OS command injection attacks. An attacker exploiting this flaw could execute arbitrary code on affected systems, potentially leading to data theft, system compromise, unauthorized modifications, or service disruption on Linux deployments running NemoClaw.
Technical details
The vulnerability is an OS command injection flaw in the NIM (NIM management) component of NVIDIA NemoClaw for Linux. The root cause involves insufficient input validation or sanitization when handling user-supplied data that is passed to system shell commands. An attacker with network access to the affected component can inject malicious OS commands that are executed with the privileges of the NemoClaw process, leading to remote code execution. The vulnerability allows an attacker to achieve code execution, data tampering, information disclosure, and denial of service. NVIDIA has published advisory information in their product security repository.
Affected products
- NVIDIA NemoClaw <UNKNOWN>
Timeline
- 2026-08-25: disclosed