How One Malicious Page Can Hijack Your Local AI Model
9 Articles
9 Articles
NemoClaw’s AI can be poisoned through a browser tab
A vulnerability affecting Nvidia’s NemoClaw could let an attacker gain control of the local Ollama model server through a single malicious website visit on the victim’s machine. According to a Cyera research, the flaw could give attackers unauthenticated access to the server, allowing them to plant instructions into the model that persist across future conversations. The attacker doesn’t directly connect to the victim’s Ollama server from the in…
How One Malicious Page Can Hijack Your Local AI Model
Security researchers have uncovered a vulnerability that lets a single webpage seize control of a local AI setup running on a user’s machine. The flaw sits inside NVIDIA’s NemoClaw tool, which integrates with the popular Ollama backend to power on-device inference. Visit the wrong site, and an attacker can rewrite the model’s instructions so every future conversation carries hidden directives chosen by the adversary. This isn’t theoretical. Oasi…
NVIDIA NemoClaw Vulnerability Lets Attackers Hijack AI Agents via DNS Rebinding
A critical vulnerability in NVIDIA NemoClaw, tracked as CVE-2026-65105, could enable attackers to gain persistent control of locally deployed AI agents through a single visit to a malicious website. Researchers Elad Luz and Ofek Itach from Oasis Security discovered that NemoClaw’s local Ollama configuration exposes an unauthenticated API, making it susceptible to DNS rebinding attacks. An attacker could modify the AI model’s chat template, silen…
A security failure in the integration between NVIDIA NemoClaw and Ollama may allow a malicious website to reach a locally executed AI server and change the behavior of models without the user noticing. The attack combines DNS rebinding with a network configuration that can leave the Ollama API accessible beyond the local interface. The discovery, presented by Oasis Security, shows a worrying scenario for those who use local LLMs and AI agents. A…
NVIDIA NemoClaw Flaw Lets Attackers Hijack AI Agents With One Website Visit
A critical vulnerability in NVIDIA NemoClaw that could let attackers hijack an AI agent after a victim visits a malicious website. The issue, tracked as CVE-2026-65105, can expose the local Ollama model server used by NemoClaw and allow persistent poisoning of the AI model’s behavior. NemoClaw is NVIDIA’s tool for deploying the OpenClaw AI agent inside an OpenShell sandbox. It can use Ollama for local inference, allowing developers to run langua…
Malicious websites can contaminate your local AI model behind NVIDIA NemoClaw.
Coverage Details
Bias Distribution
- 100% of the sources are Center
Factuality
To view factuality data please Upgrade to Premium






