Nvidia Nemoclaw vulnerabilities
14 known vulnerabilities affecting nvidia/nemoclaw.
Total CVEs
14
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL3HIGH8MEDIUM3
Vulnerabilities
Page 1 of 1
CVE-2026-65098P3CRITICALCVSS 9.8≤ 0.0.4v0 to 0.0.42026-08-25
CVE-2026-65098 [CRITICAL] CWE-1390 CVE-2026-65098: NVIDIA NemoClaw for Linux contains a vulnerability in its remote-access helper workflow, where an at
NVIDIA NemoClaw for Linux contains a vulnerability in its remote-access helper workflow, where an attacker could cause weak authentication. A successful exploit of this vulnerability might lead to code execution, information disclosure, and data tampering.
nvd
CVE-2026-65084P3CRITICALCVSS 9.8v0.0.1v0 to 0.0.12026-08-25
CVE-2026-65084 [CRITICAL] CWE-295 CVE-2026-65084: NVIDIA NemoClaw for Linux contains a vulnerability in its deployment process, where an attacker coul
NVIDIA NemoClaw for Linux contains a vulnerability in its deployment process, where an attacker could cause improper certificate validation. A successful exploit of this vulnerability might lead to information disclosure, data tampering, code execution, and escalation of privileges.
nvd
CVE-2026-65081P3CRITICALCVSS 9.8≤ 0.0.21v0 to 0.0.212026-08-25
CVE-2026-65081 [CRITICAL] CWE-494 CVE-2026-65081: NVIDIA NemoClaw for Linux contains a vulnerability in its installation process, where an attacker co
NVIDIA NemoClaw for Linux contains a vulnerability in its installation process, where an attacker could cause execution of untrusted code. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, information disclosure, and denial of service.
nvd
CVE-2026-24222P3HIGHCVSS 8.6fixed in 0.0.18vAll versions prior to v0.0.182026-04-28
CVE-2026-24222 [HIGH] CWE-497 CVE-2026-24222: NVIDIA NeMoClaw contains a vulnerability in the sandbox environment initialization component, where
NVIDIA NeMoClaw contains a vulnerability in the sandbox environment initialization component, where a remote attacker could cause improper access control by sending prompt-injected content that causes the agent to read and exfiltrate host environment variables not properly restricted during sandbox creation. A successful exploit of this vulnerability m
nvd
CVE-2026-65097P3HIGHCVSS 8.8≤ 0.0.21v0 to 0.0.212026-08-25
CVE-2026-65097 [HIGH] CWE-494 CVE-2026-65097: NVIDIA NemoClaw for Linux contains a vulnerability in its installation scripts, where an attacker co
NVIDIA NemoClaw for Linux contains a vulnerability in its installation scripts, where an attacker could cause a download of code without integrity check. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, information disclosure, and data tampering.
nvd
CVE-2026-65096P3HIGHCVSS 7.8v0.0.1v0 to 0.0.12026-08-25
CVE-2026-65096 [HIGH] CWE-78 CVE-2026-65096: NVIDIA NemoClaw for Linux contains a vulnerability in the Telegram bridge component, where an attack
NVIDIA NemoClaw for Linux contains a vulnerability in the Telegram bridge component, where an attacker could cause an OS command injection. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, information disclosure, and data tampering.
nvd
CVE-2026-65099P3HIGHCVSS 7.8v0.0.1v0 to 0.0.12026-08-25
CVE-2026-65099 [HIGH] CWE-78 CVE-2026-65099: NVIDIA NemoClaw for Linux contains a vulnerability in its command-line interface, where an attacker
NVIDIA NemoClaw for Linux contains a vulnerability in its command-line interface, where an attacker could cause OS command injection. A successful exploit of this vulnerability might lead to code execution, data tampering, information disclosure, and denial of service.
nvd
CVE-2026-65089P3HIGHCVSS 7.8≤ 0.0.3v0 to 0.0.32026-08-25
CVE-2026-65089 [HIGH] CWE-78 CVE-2026-65089: NVIDIA NemoClaw for Linux contains a vulnerability in its status and logs plugin commands, where an
NVIDIA NemoClaw for Linux contains a vulnerability in its status and logs plugin commands, where an attacker could cause OS command injection. A successful exploit of this vulnerability might lead to code execution, data tampering, information disclosure, and denial of service.
nvd
CVE-2026-65090P3HIGHCVSS 7.8≤ 0.0.17v0 to 0.0.172026-08-25
CVE-2026-65090 [HIGH] CWE-78 CVE-2026-65090: NVIDIA NemoClaw for Linux contains a vulnerability in its NIM management component, where an attacke
NVIDIA NemoClaw for Linux contains a vulnerability in its NIM management component, where an attacker could cause OS command injection. A successful exploit of this vulnerability might lead to code execution, data tampering, information disclosure, and denial of service.
nvd
CVE-2026-65105P3HIGHCVSS 8.1≤ 0.0.25v0 to 0.0.252026-08-25
CVE-2026-65105 [HIGH] CWE-306 CVE-2026-65105: NVIDIA NemoClaw for Linux contains a vulnerability in its inference server setup, where a remote att
NVIDIA NemoClaw for Linux contains a vulnerability in its inference server setup, where a remote attacker may access the inference service without authentication. A successful exploit of this vulnerability may lead to information disclosure and denial of service.
nvd
CVE-2026-65082P3HIGHCVSS 7.8≤ 0.0.17v0 to 0.0.172026-08-25
CVE-2026-65082 [HIGH] CWE-94 CVE-2026-65082: NVIDIA NemoClaw for Linux contains a vulnerability in its migration command, where a local attacker
NVIDIA NemoClaw for Linux contains a vulnerability in its migration command, where a local attacker could cause code injection. A successful exploit of this vulnerability might lead to code execution, data tampering, information disclosure, and denial of service.
nvd
CVE-2026-24231P4MEDIUMCVSS 6.3fixed in 0.0.13vAll versions prior to v0.0.132026-04-28
CVE-2026-24231 [MEDIUM] CWE-918 CVE-2026-24231: NVIDIA NemoClaw contains a vulnerability in the validateEndpointUrl() SSRF protection component, whe
NVIDIA NemoClaw contains a vulnerability in the validateEndpointUrl() SSRF protection component, where an attacker could cause a server-side request forgery by supplying a crafted endpoint URL referencing the 0.0.0.0/8 address range through a blueprint configuration file or CLI flag. A successful exploit of this vulnerability may lead to information
nvd
CVE-2026-65087P4MEDIUMCVSS 6.1v0.0.1v0 to 0.0.12026-08-25
CVE-2026-65087 [MEDIUM] CWE-522 CVE-2026-65087: NVIDIA NemoClaw contains a vulnerability where an attacker could cause insufficiently protected cred
NVIDIA NemoClaw contains a vulnerability where an attacker could cause
insufficiently protected credentials . A successful exploit of this vulnerability might lead to information disclosure and data tampering.
nvd
CVE-2026-65088P4MEDIUMCVSS 5.5≤ 0.0.17v0 to 0.0.172026-08-25
CVE-2026-65088 [MEDIUM] CWE-214 CVE-2026-65088: NVIDIA NemoClaw contains a vulnerability where an attacker could cause invocation of process using v
NVIDIA NemoClaw contains a vulnerability where an attacker could cause
invocation of process using visible sensitive information. A successful exploit of this vulnerability might lead to information disclosure.
nvd