NVIDIA NemoClaw Vulnerability Allows AI Model Poisoning via Malicious Webpage

NVIDIA NemoClaw Vulnerability Allows AI Model Poisoning via Malicious Webpage

First seen 25 Aug 2026, 16:23 UTC ThehackernewsFeeds.4Sysops 57.8

Article Content

Browse articles
ThreatCluster

A newly discovered flaw in NVIDIA's NemoClaw can allow attackers to poison local AI agents by simply visiting a malicious webpage. This vulnerability affects the Ollama server, which is used by NemoClaw, enabling permanent alterations to how AI agents interpret future conversations. The issue is particularly concerning for deployments that expose Ollama beyond the local machine. NVIDIA has released a safeguard in version 0.0.106 of NemoClaw to block this vulnerable configuration, but administrators are advised to verify their deployments and update older installations. The potential for exploitation underscores the importance of maintaining up-to-date security measures.

Key Points: • NVIDIA NemoClaw flaw allows AI model poisoning through a malicious webpage. • Affected systems include local Ollama servers used by NemoClaw. • NVIDIA released a safeguard in version 0.0.106, but older installations remain vulnerable.

Timeline

2026-08-25
NVIDIA NemoClaw vulnerability disclosed
A flaw allowing AI model poisoning via malicious webpages was reported, affecting Ollama servers.
Feeds.4Sysops
2026-08-25
NVIDIA releases safeguard
Version 0.0.106 of NemoClaw includes a safeguard to block the vulnerable configuration.
Feeds.4Sysops