CVE Tools
Back to feed

A Malicious Webpage Could Poison Your Local AI Model Behind NVIDIA NemoClaw

The Hacker News·By The Hacker News··5 min read
CVE Tools coverage

Oasis Security has disclosed a vulnerability in NVIDIA NemoClaw that permits attackers to hijack local Ollama instances via malicious webpages, specifically on Windows and WSL configurations. By exploiting DNS rebinding against unauthenticated API endpoints bound to all network interfaces, threat actors can inject hidden instructions into AI model chat templates, thereby compromising agent behavior without user knowledge. While a patch for macOS and Linux is available in NemoClaw v0.0.35, affected Windows users should restrict exposure of port 11434, as no specific fix has yet been released for those platforms.