Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
2506 articles · 132057 vulns · 36/41 feeds (7d)
← Back to list
8.6
CVE-2026-24222
nvidia · nemoclaw

CVE-2026-24222: NVIDIA NeMoClaw contains a vulnerability in the sandbox environment initialization component, where a remote attacker co

Description

NVIDIA NeMoClaw contains a vulnerability in the sandbox environment initialization component, where a remote attacker could cause improper access control by sending prompt-injected content that causes the agent to read and exfiltrate host environment variables not properly restricted during sandbox creation. A successful exploit of this vulnerability might lead to information disclosure.

Affected Products

VendorProductVersions
nvidianemoclawAll versions prior to v0.0.18

References

  • https://nvd.nist.gov/vuln/detail/CVE-2026-24222
  • https://www.cve.org/CVERecord?id=CVE-2026-24222
  • https://nvidia.custhelp.com/app/answers/detail/a_id/5837

Related News (1 articles)

Tier C
VulDB7d ago
CVE-2026-24222 | NVIDIA NemoClaw exposure of sensitive system information to an unauthorized control sphere
→ No new info (linked only)
CVSS 3.18.6 HIGH
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
CISA KEV❌ No
Actively exploited❌ No
CWECWE-497
PublishedApr 28, 2026
Trending Score14
Source articles1
Independent1
Info Completeness0/14
Missing: cve_id, title, description, vendor, product, versions, cvss, epss, cwe, kev, exploit, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

HIGHCVE-2026-31739
crypto: tegra - Add missing CRYPTO_ALG_ASYNC
Trending: 31
CRITICALPRE-CVE
Rowhammer Attack Against NVIDIA Chips
Trending: 30
CRITICALCVE-2026-24178EXP
CVE-2026-24178: NVIDIA NVFlare Dashboard contains a vulnerability in the user management and authentication system where an unauthentica
Trending: 20
HIGHCVE-2026-24186EXP
CVE-2026-24186: NVIDIA FLARE SDK contains a vulnerability in FOBS, where an attacker may cause deserialization of untrusted data by sen
Trending: 15
MEDIUMCVE-2026-24204EXP
CVE-2026-24204: NVIDIA Flare SDK contains a vulnerability where an Attacker may cause an Improper Input Validation by path traversing. A
Trending: 12

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Apr 28, 2026
Discovered by ZDM
Apr 28, 2026