logo

NVIDIA Patches High-Severity “Prompt Injection” Flaw in NemoClaw

ID: ef730fce-c1e8-5d1f-8bc8-a882c3261c44

STIX ID: report--ef730fce-c1e8-5d1f-8bc8-a882c3261c44

Feed Name: securityonline.info

Threat Score
70/100

Date Published: 2026-04-30

Date Updated: 2026-04-30

Author: Ddos

...
...

NVIDIA released a security update for NemoClaw addressing CVE-2026-24222, a high-severity prompt-injection flaw in sandbox initialization that can cause agents to read and exfiltrate host environment variables (CVSS 8.6), and CVE-2026-24231, a Medium-severity SSRF in validateEndpointUrl (CVSS 5.9); users should upgrade to v0.0.18 or later from the official repository to mitigate these issues.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.