NemoClaw vulnerability lets local AI be poisoned
🛡️ A vulnerability in Nvidia's NemoClaw can let a malicious website trick a browser into reaching a locally running Ollama model server via DNS rebinding, giving unauthenticated API access. Cyera researchers showed an attacker could modify a model's chat template to inject persistent, hidden instructions that survive future sessions. Nvidia has patched macOS and Linux builds in NemoClaw 0.0.35, while Windows/WSL remains unpatched.
