Junglewise Threat Intelligence

CVE-2026-65099: NVIDIA NemoClaw command-line interface OS command injection

CVE-2026-65099 · Severity: high · CVSS 7.8 · Published 2026-08-25

Technologies: Nvidia Nemoclaw, Linux Kernel. Vendors: Nvidia, Linux.

Executive brief

NVIDIA NemoClaw is a command-line tool for Linux used by developers and system administrators. The tool fails to properly validate user input to its CLI, allowing an attacker to inject arbitrary operating system commands. A successful attack could lead to unauthorized code execution, data theft, file manipulation, or service disruption on affected systems.

Technical details

The vulnerability is an OS command injection flaw in NVIDIA NemoClaw's command-line interface caused by insufficient input validation. An attacker can inject shell metacharacters or commands through CLI parameters without requiring authentication or special privileges. Exploitation requires the attacker to either interact with a user running the tool or have local/network access to invoke the CLI directly. A successful exploit grants the attacker the ability to execute arbitrary OS commands with the privileges of the user running NemoClaw, potentially leading to code execution, information disclosure, and denial of service. NVIDIA has released a security advisory and patched versions are expected to be available.

Affected products

  • NVIDIA NemoClaw <UNKNOWN>

Timeline

  • 2026-08-25: disclosed

References

Related threats