


Perceptive Security
SOC/SIEM Consultancy

NVIDIA NemoClaw for Linux contains a vulnerability in its installation scripts, where an attacker could cause a download of code without integrity check. A succ…
Published:
25 August 2026 at 00:00:00
Alert date:
26 August 2026 at 00:05:41
Source:
nvd.nist.gov
Operating Systems, Supply Chain & Dependencies
CVE-2026-65097 describes a vulnerability in NVIDIA NemoClaw for Linux affecting its installation scripts. The flaw allows an attacker to trigger a download of code without integrity verification, commonly known as a 'download without integrity check' weakness. Successful exploitation could lead to arbitrary code execution, privilege escalation, information disclosure, and data tampering. The vulnerability resides specifically in the installation/setup phase of the software. NVIDIA has published a security advisory via their product-security GitHub repository. The vulnerability is rated high severity given the breadth of potential impact. Linux systems running NVIDIA NemoClaw are the primary affected targets. Users are advised to review NVIDIA's official advisory for patches and mitigations.
Technical details
Mitigation steps:
Affected products:
NVIDIA NemoClaw for Linux
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-65097
https://github.com/NVIDIA/product-security/tree/main/2026/5872
https://www.cve.org/CVERecord?id=CVE-2026-65097
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
