Executive brief
NVIDIA OpenShell is a system shell utility available across all platforms. A malicious gateway could inject arbitrary operating system commands, leading to unauthorized code execution, data tampering, and information disclosure on affected systems.
Technical details
The vulnerability is an OS command injection flaw in NVIDIA OpenShell that arises from improper input validation when processing gateway communications. An attacker operating a malicious gateway can craft specially formatted commands that bypass input sanitization, enabling arbitrary OS command execution in the context of the OpenShell process. No authentication or user interaction is required beyond the system's communication with a compromised or attacker-controlled gateway. A successful exploit allows remote code execution, data tampering, and information disclosure. NVIDIA has released patches to address this vulnerability.
Affected products
- NVIDIA OpenShell all platforms
Timeline
- 2026-08-25: disclosed