
Oasis Security Uncovers Vulnerability in NVIDIA NemoClaw Allowing AI Model Manipulation via Malicious Webpages
cybersecurityvulnerabilityAImalwareNVIDIAOllamaweb_exploitunauthenticated_access
Oasis Security disclosed a vulnerability in NVIDIA NemoClaw that allows an attacker-controlled webpage to gain unauthenticated control of a local Ollama instance serving an AI agent. The flaw enables hidden instructions to be planted directly into the AI model itself. The findings were shared with The Hacker News prior to publication, and Oasis Security reported the issue to NVIDIA’s Product Security Incident Response Team. No specific CVE ID, technical exploit details, or patch release date were mentioned in the report. The impact includes unauthorized manipulation of AI models via malicious web content.