← Back to feed
Vulnerabilities & PatchesEmerging1 sourceAug 26, 2026 · 11:35via CSO Online

NemoClaw’s AI can be poisoned through a browser tab

Brief

A vulnerability affecting Nvidia’s NemoClaw could let an attacker gain control of the local Ollama model server through a single malicious website visit on the victim’s machine. According to a Cyera research, the flaw could give attackers unauthenticated access to the server, allowing them to plant instructions into the model that persist across future conversations.

The attacker doesn’t directly connect to the victim’s Ollama server from the internet. Instead, the malicious webpage tricks the browser into reaching the locally running Ollama API through DNS rebinding. Once that happens, the model’s chat template, a layer that controls how messages are presented to the model, is manipulated to add malicious instructions to the agent’s system prompts.

Read more on CSO Online