Home / Aug 26, 2026 / Story
0
#5 The Hacker News general August 25, 2026 at 14:07 UTC

A Malicious Webpage Could Poison Your Local AI Model Behind NVIDIA NemoClaw

By [email protected] (The Hacker News)

AI Summary

Oasis Security disclosed a vulnerability in NVIDIA NemoClaw (OpenClaw) that allows an attacker-controlled webpage to gain unauthenticated access to a local Ollama API instance, enabling persistent poisoning of AI agent model instructions. The attack requires no authentication and can persist hidden instructions inside the model itself, representing a novel supply-chain-style risk for AI agent deployments.

Relevance score: 80.0/100

# More from August 26