< BACK TO NEWS
importantSYS.SOURCE: The Hacker News2026-08-25T19:37:37+05:30

Vulnerability in NVIDIA NemoClaw Allows Malicious Webpages to Poison Local AI Models

A vulnerability in NVIDIA NemoClaw allows malicious webpages to compromise local AI models by exploiting unauthenticated Ollama API access, enabling persistent instruction injection. The issue persists on Windows and WSL due to improper host binding configurations, though macOS and Linux have received patches.

Oasis Security has disclosed a weakness in NVIDIA NemoClaw that could let an attacker-controlled webpage take unauthenticated control of the local Ollama instance serving an AI agent and plant hidden instructions inside the model itself.

The findings were shared with The Hacker News ahead of publication, and the report says Oasis Security reported them to NVIDIA's Product Security Incident

Read original article

*** END OF TRANSMISSION ***