Malicious Webpage Could Poison Local AI Model via NVIDIA NemoClaw
Executive Summary
Oasis Security discovered that a malicious webpage can gain unauthenticated control over a local Ollama instance used by NVIDIA NemoClaw, allowing the attacker to embed hidden instructions into the AI model. The vulnerability was reported to NVIDIA and shared with The Hacker News.
Intelligence Metadata - Source Publisher: The Hacker News - Published Date: 2026-08-25T14:07:37+00:00 - Category: threat-intel
Original Description: Oasis Security has disclosed a weakness in NVIDIA NemoClaw that could let an attacker-controlled webpage take unauthenticated control of the local Ollama instance serving an AI agent and plant hidden instructions inside the model itself. The findings were shared with The Hacker News ahead of publication, and the report says Oasis Security reported them to NVIDIA's Product Security Incident
"It is through science that we prove, but through intuition that we discover."
— Jules Poincare