Executive brief
NVIDIA NemoClaw is a software package used in machine learning and AI applications. Its installation scripts contain a vulnerability that allows an attacker to trick the system into downloading and executing malicious code without verifying the code's authenticity. This could give an attacker full control over the system, access to sensitive data, or the ability to modify stored information.
Technical details
NemoClaw for Linux contains an insecure code download vulnerability in its installation scripts, where downloaded code is not validated for integrity before execution. The attack vector requires the attacker to perform a man-in-the-middle or DNS hijacking attack to redirect code downloads to malicious sources. A successful exploit results in arbitrary code execution with the privileges of the installation process, potentially leading to privilege escalation, information disclosure, and data tampering. Patching or integrity verification mechanisms are recommended to mitigate this vulnerability.
Affected products
- NVIDIA NemoClaw <UNKNOWN>
Timeline
- 2026-08-25: disclosed