Server-Side Request Forgery Vulnerability in NVIDIA NemoClaw Product
CVE-2026-24231
6.3MEDIUM
What is CVE-2026-24231?
NVIDIA NemoClaw has a vulnerability in its SSRF protection mechanism within the validateEndpointUrl() function. By supplying a specially crafted endpoint URL that points to the 0.0.0.0/8 address range through either a blueprint configuration file or command-line interface flag, an attacker can exploit this issue. Successfully executing this attack may lead to the disclosure of sensitive information from the server.
Affected Version(s)
NemoClaw All All versions prior to v0.0.13