A critical vulnerability in NVIDIA NemoClaw that could let attackers hijack an AI agent after a victim visits a malicious website. The issue, tracked as CVE-2026-65105, can expose the local Ollama model server used by NemoClaw and allow persistent poisoning of the AI model’s behavior. NemoClaw is NVIDIA’s tool for deploying the OpenClaw AI agent inside an OpenShell sandbox. It can use Ollama for local inference, allowing developers to run language models on their own systems instead of sending prompts and source code to cloud-hosted AI services. According to Cyera, the problem begins with how NemoClaw configures Ollama. To let an OpenShell Docker container connect to Ollama running on the host, NemoClaw starts the service with...
Les hele artikkelen hos kilden.
Kommentarer (0)
Ingen kommentarer ennå. Bli den første til å kommentere!