NVIDIA NemoClaw flaw lets malicious webpages poison local AI models

Oasis Security disclosed a weakness in NVIDIA NemoClaw that lets an attacker-controlled webpage take unauthenticated control of the local Ollama instance and plant hidden instructions in the model. Fixed in v0.0.35 on macOS/Linux; no fix for Windows/WSL.
Featured · Elad Luz
1 source
Daily brief
Get tomorrow's AI brief in your inbox
More stories today
- Nvidia faces investor scrutiny on AI investments
- Lyft builds self-serve AI agent platform with LangGraph and LangSmith
- LangChain: context engineering is key AI skill
- LangChain introduces Structured Tools for complex agent inputs
- LangChain releases multi-vector retriever cookbooks for RAG on tables, text, and images