Security News

Cybersecurity news aggregator

CRITICAL Vulnerabilities SC Media

Nvidia NemoClaw vulnerability allows full control of AI agent's local model server

The vulnerability CVE-2026-65105 in Nvidia NemoClaw allows attackers to gain full control of the local Ollama server via a DNS rebinding attack from a malicious website, bypassing origin checks to access the unauthenticated API. This enables model enumeration, data theft, and the injection of malicious system prompts to poison the AI agent's behavior. The flaw resides in the tool's configuration and integration, and while Ollama has addressed similar issues, NemoClaw remains susceptible when improperly configured.
Read Full Article →

AI/ML Nvidia NemoClaw vulnerability allows full control of AI agent’s local model server August 26, 2026 Share By SC Staff Researchers at Oasis Security have disclosed a vulnerability in Nvidia Corp.’s NemoClaw, a tool designed to enhance AI agents. This flaw grants attackers complete control over the local model server powering a developer's AI agent, based on information published by Silicon Angle. The vulnerability, identified as CVE-2026-65105, can be exploited by visiting a malicious website. It allows an attacker to gain full control of the Ollama server, which NemoClaw uses to run AI models locally. The exploit bypasses security measures by leveraging DNS rebinding to circumvent origin checks and accessing Ollama's unauthenticated API. Attackers can then enumerate installed models, steal sensitive information like the machine's public key, or poison models by injecting hidden system prompts. This poisoning allows malicious instructions to be appended to every message sent by the agent, potentially causing it to write insecure code or exfiltrate conversation data. Experts note that the vulnerability lies in the "plumbing" around the AI model rather than the model itself, highlighting risks in how these components are interconnected and exposed. While Ollama has previously addressed similar exposures, the current design of NemoClaw, when configured improperly, remains susceptible. Source: Silicon Angle An In-Depth Guide to AI Get essential knowledge and practical strategies to use AI to better your security program. Learn More SC Staff Related AI/ML Nucleus Security unveils AI engine to enhance exposure management SC Staff August 26, 2026 Nucleus Helix integrates with the company's existing Data Core, which stores asset, vulnerability, and ownership information. AI benefits/risks Why human-speed defense has failed David Mytton August 26, 2026 Defenders need AI today so they can run at the same speed as the attackers. AI/ML Linux Foundation to govern TRACE specification for AI agent security SC Staff August 26, 2026 TRACE, developed by OPAQUE in collaboration with AMD, Intel, Microsoft, and the Technology Innovation Institute, creates a hardware-backed, cryptographically verifiable record. Get daily email updates SC Media's daily must-read of the most current and pressing daily news Business Email By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy . Subscribe You can skip this ad in 5 seconds

Share this article