NemoClaw’s AI can be poisoned through a browser tab

Summary

A vulnerability in Nvidia's NemoClaw could allow attackers to poison local Ollama model servers through a single malicious website visit, enabling them to inject persistent malicious instructions into AI agents. The flaw, identified as CVE-2026-65105, is exploited via DNS rebinding, giving unauthenticated access to the server and manipulating the model's system prompts. Nvidia has since patched the vulnerability for non-Windows systems.

IFF Assessment

FOE

This vulnerability allows attackers to compromise AI agents by injecting malicious instructions, posing a direct threat to defenders by enabling persistent, hard-to-detect manipulation of AI systems.

Severity

8.1 High

Defender Context

Defenders should be aware of the risks associated with AI agents, especially those that can be controlled via local servers and are susceptible to DNS rebinding attacks. This incident highlights the need for robust security measures and continuous monitoring of AI agent interactions and configurations, as they are increasingly becoming targets for sophisticated attacks.

Read Full Story →