NVIDIA Isaac-GR00T Code Injection Vulnerability Allowing Code Execution and Privilege Escalation
Vulnerability
A code injection vulnerability has been identified in the Python component of NVIDIA Isaac-GR00T, affecting all platforms. This vulnerability allows an attacker to inject malicious code, which could be executed, potentially leading to unauthorized code execution, escalation of privileges, information disclosure, and data tampering.
Impact
Exploitation of this vulnerability could result in unauthorized code execution, elevated privileges, disclosure of sensitive information, and unauthorized modification of data.
Remediation
Users are advised to update to the version of NVIDIA Isaac-GR00T that includes code commit 7f53666. This update is available on the NVIDIA Isaac-GR00T GitHub repository.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
