Vulnerabilities
Vulnerable Software
Nvidia:  >> Nemoclaw  >> 0.0.15  Security Vulnerabilities
NVIDIA NemoClaw for Linux contains a vulnerability in its installation scripts, where an attacker could cause a download of code without integrity check. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, information disclosure, and data tampering.
CVSS Score
7.5
EPSS Score
0.002
Published
2026-08-25
NVIDIA NemoClaw for Linux contains a vulnerability in its inference server setup, where a remote attacker may access the inference service without authentication. A successful exploit of this vulnerability may lead to information disclosure and denial of service.
CVSS Score
8.1
EPSS Score
0.003
Published
2026-08-25
NVIDIA NemoClaw contains a vulnerability where an attacker could cause invocation of process using visible sensitive information. A successful exploit of this vulnerability might lead to information disclosure.
CVSS Score
5.5
EPSS Score
0.001
Published
2026-08-25
NVIDIA NemoClaw for Linux contains a vulnerability in its NIM management component, where an attacker could cause OS command injection. A successful exploit of this vulnerability might lead to code execution, data tampering, information disclosure, and denial of service.
CVSS Score
7.8
EPSS Score
0.007
Published
2026-08-25
NVIDIA NemoClaw for Linux contains a vulnerability in its installation process, where an attacker could cause execution of untrusted code. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, information disclosure, and denial of service.
CVSS Score
8.1
EPSS Score
0.003
Published
2026-08-25
NVIDIA NemoClaw for Linux contains a vulnerability in its migration command, where a local attacker could cause code injection. A successful exploit of this vulnerability might lead to code execution, data tampering, information disclosure, and denial of service.
CVSS Score
7.0
EPSS Score
0.002
Published
2026-08-25
NVIDIA NeMoClaw contains a vulnerability in the sandbox environment initialization component, where a remote attacker could cause improper access control by sending prompt-injected content that causes the agent to read and exfiltrate host environment variables not properly restricted during sandbox creation. A successful exploit of this vulnerability might lead to information disclosure.
CVSS Score
8.6
EPSS Score
0.004
Published
2026-04-28


Contact Us

Shodan ® - All rights reserved