CVE-2026-65083 PUBLISHED

Assigner: nvidia
Reserved: 21.07.2026 Published: 25.08.2026 Updated: 25.08.2026

NVIDIA OpenShell for Linux contains a vulnerability in its sandbox provisioning API, where an attacker could cause an incomplete list of disallowed inputs. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, information disclosure, data tampering, and denial of service.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
CVSS Score: 9.9

Product Status

Vendor NVIDIA
Product OpenShell
Versions Default: unaffected
  • Version 0 to 0.0.33 is affected

References

Problem Types

  • CWE-184 Incomplete List of Disallowed Inputs CWE

Impacts

  • code execution, escalation of privileges, data tampering, denial of service, information disclosure