CVE-2026-65091

8.8

NVIDIA · OpenShell

NVIDIA OpenShell contains an OS command injection vulnerability triggered by a malicious gateway, which could allow arbitrary code execution.

Executive summary

A critical OS command injection vulnerability in NVIDIA OpenShell may allow unauthenticated remote attackers to execute arbitrary system commands via a malicious gateway.

Vulnerability

The software fails to properly neutralize special elements used in OS commands (CWE-78), allowing an attacker to inject and execute arbitrary commands. According to the CVSS vector (AV:N/PR:N/UI:R), this vulnerability can be triggered remotely without authentication, though it requires user interaction.

Business impact

Successful exploitation of this vulnerability leads to full system compromise, as the attacker can execute arbitrary commands with the privileges of the application. Given the CVSS score of 8.8, this poses a significant risk to data confidentiality, integrity, and availability. Compromise of the gateway environment may also facilitate lateral movement into more sensitive areas of the corporate network.

Remediation

Immediate Action: Update NVIDIA OpenShell to a patched version beyond 0.0.33 as provided in the vendor security advisory.

Proactive Monitoring: Review system logs for unusual process execution patterns or unexpected shell commands originating from the gateway service.

Compensating Controls: Deploy Web Application Firewall (WAF) rules designed to detect and block common OS command injection sequences in incoming traffic.

Exploitation status

Public Exploit Available: No (exploit_available: false)

Analyst recommendation

The high CVSS score reflects the severe potential impact of this vulnerability. Administrators should prioritize updating all instances of NVIDIA OpenShell immediately to eliminate the command injection vector.

More NVIDIA CVEs