Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.8

CVE-2026-65081: NVIDIA NemoClaw Linux installer can run malicious code

CVE-2026-65081 · published 9 days ago
Summary

The installer for NVIDIA NemoClaw on Linux may allow an attacker to insert and run their own code. If exploited, this could let the attacker take control of the system, modify or steal data, and cause it to stop working. Apply the latest security update or reinstall with a trusted source to protect your environment.

What to do

The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.

Affected software
VendorProductAffected versions
nvidia nemoclaw <= 0.0.21
cpe:2.3:a:nvidia:nemoclaw:*:*:*:*:*:*:*:*
Original advisory text
NVIDIA NemoClaw for Linux contains a vulnerability in its installation process, where an attacker could cause execution of untrusted code. A successful exploit of this vulnerability might lead to c...
NVIDIA NemoClaw for Linux contains a vulnerability in its installation process, where an attacker could cause execution of untrusted code. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, information disclosure, and denial of service.
Severity
9.8 Critical
CVSS 3.1: 8.1 (NVD)
Exploitation
EPSS <1%
Type
CWE-494Download of Code Without Integrity Check
Timeline
Published25 Aug 2026
Updated2 Sep 2026
First seen26 Aug 2026
Sources
Monitor software like this
Free during beta