Urgent.News

What's breaking now, across thousands of outlets.

Tech

A Malicious Webpage Could Poison Your Local AI Model Behind NVIDIA NemoClaw

Oasis Security has disclosed a weakness in NVIDIA NemoClaw that could let an attacker-controlled webpage take unauthenticated control of the local Ollama instance serving an AI agent and plant hidden instructions inside the model itself. The findings were shared with The Hacker News ahead of publication, and the report says Oasis Security reported them to NVIDIA's Product Security Incident

A Malicious Webpage Could Poison Your Local AI Model Behind NVIDIA NemoClaw

Researchers at security company Oasis Security Ltd. have uncovered a flaw in Nvidia's NemoClaw that allows attackers to take control of the model server powering a developer's AI agent. The vulnerability, CVE-2026-65105, can be exploited by visiting a malicious website once. Oasis alerted Nvidia before sharing the findings, which are the first from their team since its acquisition by Cyera in July.

NemoClaw, introduced at Nvidia's GTC conference in March, aims to run AI agents locally using Ollama instead of cloud services. Ollama is the server that attackers gain control over. While Ollama binds to 127.0.0.1 by default, NemoClaw launches it with the flag OLLAMA_HOST=0.0.0.0:11434, making it accessible from any device on the same network.

The API lacks authentication, and researchers found that the Host header check is bypassed when the bind address isn't loopback. This allows DNS rebinding attacks, where the attacker points a controlled domain at their own server and forces the victim's browser to connect to it. With full API access, an attacker can enumerate installed models, extract machine information, or even delete models.

The worst-case scenario is model poisoning, where a hidden system prompt is injected into the model, which can override the agent's system prompt. Although the sandbox provides some protection, the main risk lies in the underlying unauthenticated local model server. Oasis recommends keeping Ollama on loopback behind an authenticated proxy and checking the Host header against an allowlist.

Written by urgent.news from SiliconANGLE's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

This story

This is one outlet's version. Read the fullest account.

Read the original at thehackernews.com →

More in Tech

Facing State Management: "Truly" Understanding Provider in Flutter

The Beginning: Why This Project? You somehow learn to build UIs in Flutter, but when it comes to state management, it's a wall you inevitably hit.

  • Provider functions like a central radio station in Flutter app
  • NotifyListeners() updates UI when data changes in Provider
  • Learning strategy involved AI pair programming and error analysis

HD-101 — The first pull request

HD-101 — The first pull request Builds: nothing. Teaches: why the next six tickets exist. The ticket Add a feature to the helpdesk CLI. Don't push to main — open a pull request.

  • HD-101 is a pull request for adding a feature to prioritize tickets in a helpdesk CLI.
  • The PR lacked tests, reviewers, and status checks, serving as an example of an empty change.

More from Tuesday 25 August →