NVIDIA Isaac-GR00T Code Injection Vulnerability Allowing Privilege Escalation and Code Execution

Vulnerability

A code injection vulnerability has been identified in the Python component of NVIDIA Isaac-GR00T, affecting all platforms. This vulnerability allows an attacker to inject malicious code, which could be executed, potentially leading to unauthorized privilege escalation, disclosure of sensitive information, and tampering with data.

Impact

Exploitation of this vulnerability could result in arbitrary code execution, elevated privileges, unauthorized information access, and data modification.

Remediation

Users are advised to update to the version of NVIDIA Isaac-GR00T that includes code commit 9ca97e1. This update is available on the official NVIDIA GitHub repository.

Added: Aug 13, 2025, 9:50 PM
Updated: Aug 13, 2025, 9:50 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
5.2
remediation
7.7
relevance
0.3
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.