Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
NVIDIA NemoClaw Vulnerability Risks AI Model Security

NVIDIA NemoClaw Vulnerability Risks AI Model Security

Posted on August 25, 2026 By CWS

Oasis Security recently uncovered a critical vulnerability in NVIDIA’s NemoClaw framework, potentially enabling an attacker-controlled webpage to manipulate local AI instances and embed covert instructions within the AI model. This discovery, shared with The Hacker News before public release, highlights significant security concerns for AI implementations utilizing NVIDIA’s technology.

Details of the Vulnerability

The vulnerability stems from how NemoClaw initializes the Ollama backend, binding it to all network interfaces at OLLAMA_HOST=0.0.0.0:11434. This configuration exposes the model server’s API to unauthorized modification, allowing attackers to alter the chat template and inject hidden commands into subsequent AI interactions.

Oasis Security’s report, lacking a CVE identifier or version specifics, reveals that affected installations cannot currently verify their vulnerability status. Despite no known exploitations as of late August 2026, this oversight poses potential risks for users running vulnerable versions of NemoClaw.

Platform-Specific Configuration Issues

Different platforms introduce varied security configurations for Ollama within NemoClaw. Non-WSL hosts leverage a token-gated reverse proxy, whereas Docker Desktop on WSL bypasses this proxy due to its loopback address access through host.docker.internal. The Windows-host configuration, however, sets OLLAMA_HOST=0.0.0.0:11434, allowing Docker Desktop containers to access the daemon without authentication, thus increasing exposure risks.

The report also points out that Ollama’s integration guide recommends a similar setup for WSL2 or container environments, further extending this vulnerability. The absence of authentication on port 11434, combined with an ineffective CORS implementation, exacerbates the security gap, making it feasible for attackers to treat requests as originating from the same domain.

Implications and Required Mitigations

DNS rebinding attacks take advantage of this vulnerability by resolving the attacker’s domain to their server initially and then to 127.0.0.1. The lack of Host and Origin header verification enables these attacks, which have been documented previously. Ollama addressed a similar issue in March 2024, yet further mitigations might be necessary to protect against this newly identified threat.

The report suggests that once an attacker gains API access, they can insert a malicious Go template via /api/create, altering how messages are processed and embedding unauthorized instructions into every system message. This persistence of instructions compromises future AI interactions, posing a significant security threat.

Security researchers have documented similar attacks against other AI systems, emphasizing the need for robust template integrity checks. NVIDIA advises users on Windows-host paths to avoid exposing port 11434 to external networks, although this guidance does not fully mitigate the inherent risk of local attacks.

Looking Ahead

NVIDIA and affected users must prioritize addressing this vulnerability to safeguard AI model integrity. Enhanced security measures, including stringent header verification and controlled network exposure, are crucial to preventing unauthorized access and ensuring robust AI system security. The wider AI community should remain vigilant and implement recommended security practices to protect against such vulnerabilities.

The Hacker News Tags:AI security, API, chat template, CORS, Cybersecurity, DNS rebinding, NemoClaw, network security, Nvidia, Oasis Security, Ollama, OpenClaw, Sandbox, server vulnerability, Vulnerability

Post navigation

Previous Post: ASOS Reports External Breach of Customer Accounts
Next Post: Hackers Exploit Vulnerabilities in MiniOrange WordPress Plugin

Related Posts

Fraudsters Clone Russian Company Sites to Steal Payments Fraudsters Clone Russian Company Sites to Steal Payments The Hacker News
New TEE.Fail Side-Channel Attack Extracts Secrets from Intel and AMD DDR5 Secure Enclaves New TEE.Fail Side-Channel Attack Extracts Secrets from Intel and AMD DDR5 Secure Enclaves The Hacker News
Chinese Hackers Use Fake Tax Tools in India to Deploy DcRAT Chinese Hackers Use Fake Tax Tools in India to Deploy DcRAT The Hacker News
RomCom Uses SocGholish Fake Update Attacks to Deliver Mythic Agent Malware RomCom Uses SocGholish Fake Update Attacks to Deliver Mythic Agent Malware The Hacker News
Zombie Card Technique Revives Expired Visa Cards Zombie Card Technique Revives Expired Visa Cards The Hacker News
Cisco Fixes Critical Flaws in Identity and Webex Services Cisco Fixes Critical Flaws in Identity and Webex Services The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Marimo Notebook Flaw Allows MCP Commands in Edit Mode
  • AI Agents Compromise Asian Government Systems, Steal Data
  • Hackers Exploit Vulnerabilities in MiniOrange WordPress Plugin
  • NVIDIA NemoClaw Vulnerability Risks AI Model Security
  • ASOS Reports External Breach of Customer Accounts

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Marimo Notebook Flaw Allows MCP Commands in Edit Mode
  • AI Agents Compromise Asian Government Systems, Steal Data
  • Hackers Exploit Vulnerabilities in MiniOrange WordPress Plugin
  • NVIDIA NemoClaw Vulnerability Risks AI Model Security
  • ASOS Reports External Breach of Customer Accounts

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark