← Terug naar overzicht

CVE-2026-65097 describes a vulnerability in NVIDIA NemoClaw for Linux affecting its installation scripts. The flaw allows an attacker to trigger a download of code without integrity verification, commonly known as a 'download without integrity check' weakness. Successful exploitation could lead to arbitrary code execution, privilege escalation, information disclosure, and data tampering. The vulnerability resides specifically in the installation/setup phase of the software. NVIDIA has published a security advisory via their product-security GitHub repository. The vulnerability is rated high severity given the breadth of potential impact. Linux systems running NVIDIA NemoClaw are the primary affected targets. Users are advised to review NVIDIA's official advisory for patches and mitigations.

Affected products

  • NVIDIA NemoClaw for Linux

Related CVE's

  • CVE-2026-65097

Categories

  • Operating Systems
  • Supply Chain & Dependencies