PT-2026-35756 · Nvidia · Nemoclaw
Published
2026-04-28
·
Updated
2026-04-28
·
CVE-2026-24222
CVSS v3.1
8.6
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
NVIDIA NeMoClaw (affected versions not specified)
Description
A flaw in the sandbox environment initialization component allows a remote attacker to cause improper access control. By sending prompt-injected content, an attacker can force the agent to read and exfiltrate host environment variables that were not properly restricted during the creation of the sandbox. This can lead to information disclosure.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Nemoclaw