Junglewise Threat Intelligence

CVE-2026-65096: NVIDIA NemoClaw command injection in Telegram bridge

CVE-2026-65096 · Severity: high · CVSS 7.8 · Published 2026-08-25

Technologies: Nvidia Nemoclaw, Linux Kernel. Vendors: Nvidia, Linux.

Executive brief

NVIDIA NemoClaw is a software component for Linux that includes a Telegram integration module. An attacker could exploit a command injection flaw in the Telegram bridge to execute arbitrary OS commands, potentially leading to system compromise, data theft, or privilege escalation on affected systems.

Technical details

The vulnerability is an OS command injection flaw located in the Telegram bridge component of NVIDIA NemoClaw for Linux. The root cause is likely improper sanitization or validation of user-supplied input that is passed to system command execution functions. An attacker with local access or the ability to send messages through the Telegram bridge could inject malicious OS commands that would be executed with the privileges of the NemoClaw process. A successful exploit could result in arbitrary code execution, privilege escalation, information disclosure, and data tampering. Patches are expected to be available through NVIDIA's security advisory channels.

Affected products

  • NVIDIA NemoClaw <UNKNOWN>

Timeline

  • 2026-08-25: disclosed

References

Related threats