CVE-2026-65088CWE-214

CVE-2026-65088

Medium · published August 26, 2026

CVSS v3.1
5.5
EPSS
0%
Percentile
1.8
In the wild
Unconfirmed
What it is

NVIDIA NemoClaw contains a vulnerability where an attacker could cause

invocation of process using visible sensitive information. A successful exploit of this vulnerability might lead to information disclosure.

The record
Technical detail
CVSS v3.1
5.5 · MEDIUM
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CVSS v4.0
Not supplied
EPSS
0.00117 · 1.8th percentile
Weakness
CWE-214 · Invocation of Process Using Visible Sensitive Information
Published
2026-08-26T01:17Z
Affected products (1)
ProductVersionsFixed in
nvidia/nemoclaw≤ 0.0.17
References (3)
EPSS history
Timeline
  • 27 AUG 06:41Z
    EPSS moved — → 0%
    epss
  • 25 AUG 20:15Z
    NVIDIA NemoClaw contains a vulnerability where an attacker could cause invocation of process using visible sensitive information
    cvelistv5