Nvidia's NemoClaw Vulnerability Exposes Local AI Servers to Malicious Web Attacks

Aug 26, 2026 343 views

A significant vulnerability in Nvidia’s NemoClaw could enable an attacker to take control of a local Ollama model server by simply visiting a malicious website. Research conducted by Cyera reveals that this flaw facilitates unauthenticated access to the server, potentially enabling attackers to implant instructions within the model that persist through future interactions. The implications of this security gap extend beyond immediate data breaches; they raise concerns about the trustworthiness and integrity of AI systems at large.

The Mechanism of Attack

The exploit relies on a technique known as DNS rebinding, which tricks the browser into connecting to the locally running Ollama API instead of the attacker’s server. This manipulation allows the attacker to modify the chat template—a section that governs how messages are processed by the model—to insert harmful directives into the AI’s system prompts. How pervasive is this vulnerability? In environments where AI models are rapidly gaining traction, the potential for misuse reaches alarming levels.

According to Elad Luz, head of research at Oasis Security, “With CVE-2026-65105, an attacker can change how NemoClaw’s model interprets every incoming message. These changes endure beyond a single session, creating an integrity challenge that’s tough to detect.” Luz emphasizes that as AI agents become more like identities with real capabilities, their security must evolve beyond mere tools. The boundary between user and model can blur, which complicates traditional security measures.

DNS Rebinding Exploits Local Access

NemoClaw operates the OpenClaw AI agent within Nvidia’s OpenShell sandbox environment. For local inference, it can utilize Ollama, allowing developers to run models on their own machines instead of outsourcing computation to the cloud. That’s attractive for many in the field, especially when considering data privacy.

However, the vulnerability stems from how the OpenShell sandbox interacts with networking configurations. NemoClaw initializes Ollama on a non-loopback address (0.0.0.0:11434) to enable connections from within a Docker container, which inadvertently disables protective measures. Normally, Ollama doesn’t require authentication and employs CORS checks, but when bound to a non-loopback address, these checks are bypassed. This is a concerning oversight—one that not only opens the gate for attackers but also questions the auditing processes that should catch such flaws.

This opens the door for attackers to carry out DNS rebinding, where an initial request resolves to the attacker’s server and is subsequently redirected to 127.0.0.1 or another local address. Since the browser thinks the requests are from the attacker’s domain, Ollama grants access without verification. The simplicity of this technique is worrisome; it relies on fundamental misunderstandings of networking protocols rather than sophisticated hacking skills.

Randolph Barr, Chief Information Security Officer at Cequence Security, notes that while DNS rebinding isn’t a new trick, its consequences for local model servers highlight a worrying development in security vulnerabilities. This isn’t just a theoretical risk. It's one that can impact various organizations and developers who may not employ stringent security practices.

Researchers at Cyera discovered that once access was gained, attackers could enumerate installed models, ascertain Ollama’s version, delete models, and manipulate the local Ollama setup to consume resources. This cascade of control serves as a reminder of how interconnected and fragile these systems can be when fundamental security principles are overlooked.

The Persistence of Poisoned Templates

The most alarming aspect of this vulnerability is the aftermath of an attacker gaining access to the API. The permanence of the modifications speaks volumes about the potential for long-term manipulation.

Cyera experimented with injecting malicious directives through Ollama's model configuration. Initially, standard prompt injection tactics were insufficient, as OpenClaw employs a distinct prompt for communication. To circumvent this, the team targeted the model's chat template, allowing them to extend the model's behaviors with additional instructions. The complexity of these interactions reveals that AI systems are not just hardware or algorithms—they're dynamic and adaptable, making the security stakes even higher.

This modification occurs at the core model level, eluding detection by the OpenClaw agent, which is unable to override the manipulated settings with its own system prompt. Consequently, the altered template can persist across multiple conversations, remaining invisible in the model's regular metadata. This raises another question: How accountable are developers for vulnerabilities residing in their tools?

The implications of this exposure hinge on the access privileges assigned to the compromised agent. Cyera indicated that injected commands could potentially redirect an agent towards resources controlled by the attacker, suppress security alerts, introduce vulnerabilities, or exfiltrate sensitive data via unrestricted network access. Imagine the chaos that could ensue. Malicious actors could effectively use a compromised AI to manipulate entire systems, altering data or processes in ways that could take significant time to undo.

After the publication of this information, a spokesperson for Nvidia stated, “We acknowledge the researchers’ discovery and their report. Their work underscores the value of open-source development for collaborative security testing. Nvidia has released an update that users can download to secure their systems.” While it’s good to see Nvidia responding, the initial oversight raises questions about how such vulnerabilities are discovered in the first place.

Future Outlook and Implications

This situation serves as a wake-up call. The vulnerabilities in AI infrastructure could have far-reaching consequences for enterprises and individual developers alike. If you're working in this space, consider the security protocols you have in place. They may not be enough. As AI becomes more embedded in daily operations, the risks associated with vulnerabilities like the one found in NemoClaw demand heightened scrutiny.

This isn't just about fixing a flaw; it’s about fundamentally re-examining the approach to security in AI models. Organizations must proactively anticipate future threats and adapt their security posture accordingly. After all, the continuous evolution of attack vectors means the cat-and-mouse game of security won't let up anytime soon. The challenge lies in keeping up.

What this means for you is clear: as AI continues to grow in capability and ubiquity, investing in security isn't optional. It's a necessity. Be vigilant. The technology that's supposed to enhance productivity could also become a liability if not managed properly.

Source: Richard Martinez · www.csoonline.com

Comments

Sign in to comment.
No comments yet. Be the first to comment.

Related Articles

NemoClaw’s AI can be poisoned through a browser tab