www.darkreading.com 8/25/2026, 8:20:35 PM · external

NVIDIA NemoClaw flaw lets hackers hijack local AI via browser

NVIDIA NemoClaw flaw lets hackers hijack local AI via browser
CyberSIXT Evidence Panel
Primary Source cyera.com

THE article discusses a security vulnerability in NVIDIA's NemoClaw tool, which allows attackers to gain unauthenticated access to a local model server via the Ollama API. Researchers from Cyera identified that the configuration issue in NemoClaw exposes the API to browser-based DNS rebinding attacks. An attacker can exploit this to compromise AI agents by silently injecting malicious instructions into large language models (LLMs).

The vulnerability could lead to persistent corruption of the AI agents, as attackers can modify crucial elements like chat templates, allowing unauthorized access and potential data exfiltration. Although a fix is available for MacOS and Linux, no solution exists for Windows, highlighting the need for improved security measures and oversight regarding AI agent deployments.

View Primary Source Via www.darkreading.com

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline