CVE-2026-24222

8.6

NVIDIA · NeMoClaw

NVIDIA NeMoClaw contains a vulnerability in the sandbox environment where prompt injection allows remote attackers to exfiltrate host environment variables through improper access control.

Executive summary

A critical vulnerability in NVIDIA NeMoClaw allows unauthenticated remote attackers to exfiltrate sensitive host environment variables via prompt injection, potentially leading to unauthorized information disclosure.

Vulnerability

This vulnerability, categorized as CWE-497, exists in the sandbox environment initialization component. An unauthenticated remote attacker can exploit this flaw by sending crafted prompt-injected content, forcing the agent to bypass access controls and disclose sensitive host-level information.

Business impact

The exploitation of this vulnerability poses a significant risk to organizational confidentiality by exposing sensitive host environment variables. Given the CVSS score of 8.6, this flaw is categorized as high severity due to the potential for unauthorized access to internal system configurations, which could facilitate further lateral movement or deeper system compromise.

Remediation

Immediate Action: Update the NVIDIA NeMoClaw software to version 0.0.18 or later to resolve the sandbox initialization flaw.

Proactive Monitoring: Review system and application logs for unusual prompt patterns or unexpected agent behavior that may indicate attempts to query or exfiltrate environment variables.

Compensating Controls: Implement strict input validation or sanitization layers for all prompts processed by the NeMoClaw agent to mitigate the impact of injection attacks until the patch is applied.

Exploitation status

Public Exploit Available: No

Analyst recommendation

The severity of this vulnerability necessitates immediate attention, particularly in environments where NeMoClaw is integrated with sensitive backend infrastructure. Administrators must prioritize upgrading to version 0.0.18 to ensure that sandbox environment restrictions are correctly enforced and that host environment variables are protected from unauthorized access.

More NVIDIA CVEs

Sources