NVIDIA Isaac-GR00T Code Injection Vulnerability Allowing Remote Code Execution and Privilege Escalation

Vulnerability

A code injection vulnerability has been identified in NVIDIA Isaac-GR00T for all platforms, specifically within a Python component. This vulnerability allows an attacker to inject malicious code, which could be executed, potentially leading to unauthorized access, escalation of privileges, disclosure of sensitive information, and tampering with data.

Impact

Exploitation of this vulnerability could result in arbitrary code execution, unauthorized privilege escalation, disclosure of confidential information, and unauthorized data modification.

Remediation

Users are advised to update to the latest version of NVIDIA Isaac-GR00T that includes the security fix. Instructions for downloading the updated version can be found on the NVIDIA Product Security page.

Added: Nov 18, 2025, 5:38 PM
Updated: Nov 18, 2025, 5:38 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
10.0
exploitability
5.2
remediation
7.7
relevance
1.1
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.