{"id":"CVE-2026-65091","details":"NVIDIA OpenShell for all platforms contains a vulnerability where a malicious gateway could cause OS command injection. A successful exploit of this vulnerability might lead to code execution, data tampering, and information disclosure.","modified":"2026-09-03T11:45:58.458728286Z","published":"2026-08-25T20:15:12.853Z","database_specific":{"cwe_ids":["CWE-78"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/65xxx/CVE-2026-65091.json","unresolved_ranges":[{"extracted_events":[{"introduced":"0 to 0.0.33"},{"last_affected":"0 to 0.0.33"}],"source":"AFFECTED_FIELD"}],"cna_assigner":"nvidia"},"references":[{"type":"WEB","url":"https://github.com/NVIDIA/product-security/tree/main/2026/5872"},{"type":"WEB","url":"https://www.cve.org/CVERecord?id=CVE-2026-65091"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/65xxx/CVE-2026-65091.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-65091"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/nvidia/openshell","events":[{"introduced":"0"},{"last_affected":"e39bb380409dc36092ab80258547225830a7b06d"}],"database_specific":{"source":"CPE_RANGE","cpe":"cpe:2.3:a:nvidia:openshell:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"last_affected":"0.0.33"}]}}],"versions":["v0.0.33","v0.0.32","v0.0.31","v0.0.30","v0.0.29","v0.0.28","v0.0.27","v0.0.26","v0.0.25","v0.0.24","v0.0.23","v0.0.22","v0.0.21","v0.0.20","v0.0.18","v0.0.19","v0.0.17","v0.0.16","v0.0.15","v0.0.14","v0.0.13","v0.0.12","v0.0.11","v0.0.10","v0.0.9","v0.0.8","v0.0.7","v0.0.6","v0.0.5","v0.0.4","v0.0.3","v0.0.1"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-65091.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"}]}