漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
N/A
Vulnerability Description
NVIDIA NeMoClaw contains a vulnerability in the sandbox environment initialization component, where a remote attacker could cause improper access control by sending prompt-injected content that causes the agent to read and exfiltrate host environment variables not properly restricted during sandbox creation. A successful exploit of this vulnerability might lead to information disclosure.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
Vulnerability Type
将系统数据暴露到未授权控制的范围
Vulnerability Title
NVIDIA NeMoClaw 安全漏洞
Vulnerability Description
NVIDIA NeMoClaw是美国英伟达(NVIDIA)公司的一个大模型行为约束与安全控制框架。 NVIDIA NeMoClaw存在安全漏洞,该漏洞源于沙箱环境初始化组件问题,可能导致远程攻击者通过发送提示注入内容造成访问控制不当,导致代理读取和泄露沙箱创建期间未正确限制的主机环境变量,导致信息泄露。
CVSS Information
N/A
Vulnerability Type
N/A