importantSYS.SOURCE: The Hacker News• 2026-08-25T19:37:37+05:30
Vulnerability in NVIDIA NemoClaw Allows Malicious Webpages to Poison Local AI Models
A vulnerability in NVIDIA NemoClaw allows malicious webpages to compromise local AI models by exploiting unauthenticated Ollama API access, enabling persistent instruction injection. The issue persists on Windows and WSL due to improper host binding configurations, though macOS and Linux have received patches.
Oasis Security has disclosed a weakness in NVIDIA NemoClaw that could let an attacker-controlled webpage take unauthenticated control of the local Ollama instance serving an AI agent and plant hidden instructions inside the model itself.
The findings were shared with The Hacker News ahead of publication, and the report says Oasis Security reported them to NVIDIA's Product Security Incident
*** END OF TRANSMISSION ***