A Malicious Webpage Could Poison Your Local AI Model Behind NVIDIA NemoClaw

A Malicious Webpage Could Poison Your Local AI Model Behind NVIDIA NemoClaw
Oasis Security disclosed a weakness in NVIDIA NemoClaw that could let an attacker-controlled webpage take over a locally hosted Ollama instance and poison a model’s chat template with hidden instructions. NVIDIA fixed the issue for macOS and Linux in NemoClaw v0.0.35, but the Windows and WSL path remains unpatched and is affected by a similar 0.0.0.0 binding behavior. #NVIDIA #NemoClaw #Ollama #OpenClaw #Paperclip

Keypoints

  • Oasis Security reported the NemoClaw flaw to NVIDIA PSIRT before publication.
  • The issue could allow browser-based takeover of a local Ollama instance without authentication.
  • Attackers could modify the model chat template through the Ollama API and persist hidden instructions.
  • NemoClaw v0.0.35 fixes macOS and Linux, but the Windows and WSL path still lacks a complete fix.
  • The research shows the attack chain can work through DNS rebinding and localhost access in browser sessions.

Read More: https://thehackernews.com/2026/08/a-malicious-webpage-could-poison-your.html