CVE-2026-24222
published 2026-04-28CVE-2026-24222: NVIDIA NeMoClaw contains a vulnerability in the sandbox environment initialization component, where a remote attacker could cause improper access control by…
PriorityP352high8.6CVSS 3.1
AVNACLPRNUINSCCHINAN
EPSS
0.40%
32.6th percentile
NVIDIA NeMoClaw contains a vulnerability in the sandbox environment initialization component, where a remote attacker could cause improper access control by sending prompt-injected content that causes the agent to read and exfiltrate host environment variables not properly restricted during sandbox creation. A successful exploit of this vulnerability might lead to information disclosure.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| nvidia | nemoclaw | < 0.0.18 | 0.0.18 |
| nvidia | nemoclaw | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
NVIDIA NemoClaw exposure of sensitive system information to an unauthorized control sphere
vuldb·2026-04-28·CVSS 8.6
CVE-2026-24222 [HIGH] NVIDIA NemoClaw exposure of sensitive system information to an unauthorized control sphere
A vulnerability was found in NVIDIA NemoClaw and classified as problematic. This vulnerability affects unknown code. The manipulation results in exposure of sensitive system information to an unauthorized control sphere.
This vulnerability is known as CVE-2026-24222. It is possible to launch the attack remotely. No exploit is available.
GHSA
GHSA-mf4x-g8fr-m8pw: NVIDIA NeMoClaw contains a vulnerability in the sandbox environment initialization component, where a remote attacker could cause improper access cont
ghsa_unreviewed·2026-04-28
CVE-2026-24222 [HIGH] CWE-497 GHSA-mf4x-g8fr-m8pw: NVIDIA NeMoClaw contains a vulnerability in the sandbox environment initialization component, where a remote attacker could cause improper access cont
NVIDIA NeMoClaw contains a vulnerability in the sandbox environment initialization component, where a remote attacker could cause improper access control by sending prompt-injected content that causes the agent to read and exfiltrate host environment variables not properly restricted during sandbox creation. A successful exploit of this vulnerability might lead to information disclosure.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-04-28
Published