CVE-2026-24222: High severity Nvidia NeMoClaw vulnerability
NVIDIA NeMoClaw contains a vulnerability in the sandbox environment initialization component, where a remote attacker could cause improper access control by sending prompt-injected content that causes the agent to read and exfiltrate host environment variables not properly restricted during sandbox creation. A successful exploit of this vulnerability might lead to information disclosure.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-24222?
CVE-2026-24222 has been rated as a high severity vulnerability due to its potential impact on access control.
How do I fix CVE-2026-24222?
To mitigate CVE-2026-24222, ensure you apply the latest security patches provided by NVIDIA for NeMoClaw.
What type of attack can be executed through CVE-2026-24222?
CVE-2026-24222 can be exploited by a remote attacker using prompt injection to gain improper access to host environment variables.
What versions of NVIDIA NeMoClaw are affected by CVE-2026-24222?
CVE-2026-24222 impacts all versions of NVIDIA NeMoClaw that are not patched against this vulnerability.
How can I detect if CVE-2026-24222 has been exploited in my environment?
Monitoring for unusual access patterns or unexpected environment variable exposure can help detect exploitation of CVE-2026-24222.