logo

NVIDIA NemoClaw Vulnerability Allows AI Model Poisoning via Malicious Webpage

ID: 93fe6461-88de-5d1b-8de1-f1b115d90002

STIX ID: report--93fe6461-88de-5d1b-8de1-f1b115d90002

Feed Name: ThreatCluster

Threat Score
75/100

Date Published: 2026-08-25

Date Updated: 2026-08-26

...
...

A critical vulnerability (CVE-2026-65105) in NVIDIA's NemoClaw allows attackers to exploit a network misconfiguration and use DNS rebinding to reach the local Ollama model server, enabling unauthenticated manipulation of chat templates and persistent injection of malicious instructions; patches are available for macOS and Linux, but Windows remains vulnerable, underscoring significant risks in AI agent deployment.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.