NVIDIA Patches High-Severity “Prompt Injection” Flaw in NemoClaw
ID: ef730fce-c1e8-5d1f-8bc8-a882c3261c44
STIX ID: report--ef730fce-c1e8-5d1f-8bc8-a882c3261c44
Feed Name: securityonline.info
Threat Score
NVIDIA released a security update for NemoClaw addressing CVE-2026-24222, a high-severity prompt-injection flaw in sandbox initialization that can cause agents to read and exfiltrate host environment variables (CVSS 8.6), and CVE-2026-24231, a Medium-severity SSRF in validateEndpointUrl (CVSS 5.9); users should upgrade to v0.0.18 or later from the official repository to mitigate these issues.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
