NVIDIA NemoClaw Vulnerability Allows AI Model Poisoning via Malicious Webpage
ID: 93fe6461-88de-5d1b-8de1-f1b115d90002
STIX ID: report--93fe6461-88de-5d1b-8de1-f1b115d90002
Feed Name: ThreatCluster
Threat Score
A critical vulnerability (CVE-2026-65105) in NVIDIA's NemoClaw allows attackers to exploit a network misconfiguration and use DNS rebinding to reach the local Ollama model server, enabling unauthenticated manipulation of chat templates and persistent injection of malicious instructions; patches are available for macOS and Linux, but Windows remains vulnerable, underscoring significant risks in AI agent deployment.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
