A Malicious Webpage Could Poison Your Local AI Model Behind NVIDIA NemoClaw

Summary

A vulnerability in NVIDIA NemoClaw allows an attacker-controlled webpage to gain unauthenticated control of a local Ollama instance. This could enable an attacker to plant hidden instructions within the AI model itself.

IFF Assessment

FOE

This vulnerability allows attackers to compromise AI models, which is detrimental to defenders relying on the integrity of these systems.

Severity

8.0 High (AI Estimated)

The vulnerability allows for unauthenticated remote code execution in a critical component serving AI models. The impact on confidentiality, integrity, and availability is high, with a reasonable attack vector.

Defender Context

This highlights a critical security risk in the deployment of local AI models, especially those integrated with web services. Defenders need to be aware of potential supply chain attacks targeting AI models and ensure strict access controls and input sanitization for any web-facing components that interact with AI infrastructure.

Read Full Story →