Server-Side Request Forgery Vulnerability in NVIDIA NemoClaw Product
CVE-2026-24231

6.3MEDIUM

Key Information:

Vendor

Nvidia

Status
Vendor
CVE Published:
28 April 2026

What is CVE-2026-24231?

NVIDIA NemoClaw has a vulnerability in its SSRF protection mechanism within the validateEndpointUrl() function. By supplying a specially crafted endpoint URL that points to the 0.0.0.0/8 address range through either a blueprint configuration file or command-line interface flag, an attacker can exploit this issue. Successfully executing this attack may lead to the disclosure of sensitive information from the server.

Affected Version(s)

NemoClaw All All versions prior to v0.0.13

References

CVSS V3.1

Score:
6.3
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.