{"data":{"id":"7ae809e4-29b1-4ad0-8325-d321e20c5b8a","title":"NemoClaw’s AI can be poisoned through a browser tab","summary":"A vulnerability in Nvidia's NemoClaw allows attackers to poison a local AI model through a malicious website visit using DNS rebinding (a technique where an attacker tricks a browser into connecting to a local service by redirecting a domain name). Once the attacker gains access to the Ollama model server (the software that runs AI models locally), they can inject harmful instructions into the model's chat template (the layer controlling how messages are formatted), and these malicious instructions persist invisibly across all future conversations, making them extremely difficult to detect.","solution":"The flaw has been patched by Nvidia for non-Windows systems.","labels":["security"],"sourceUrl":"https://www.csoonline.com/article/4214156/nemoclaws-ai-can-be-poisoned-through-a-browser-tab.html","publishedAt":"2026-08-26T11:35:43.000Z","cveId":null,"cweIds":null,"cvssScore":null,"cvssSeverity":null,"severity":"high","attackType":["model_poisoning","rag_poisoning"],"issueType":"news","affectedPackages":null,"affectedVendors":["NVIDIA"],"affectedVendorsRaw":["Nvidia","NemoClaw","OpenClaw","Ollama"],"classifierModel":"claude-haiku-4-5-20251001","classifierPromptVersion":"v3","cvssVector":null,"attackVector":null,"attackComplexity":null,"privilegesRequired":null,"userInteraction":null,"exploitMaturity":null,"epssScore":null,"patchAvailable":null,"disclosureDate":"2026-08-26T11:35:43.000Z","capecIds":null,"crossRefCount":0,"attackSophistication":"moderate","impactType":["integrity","confidentiality"],"aiComponentTargeted":"model","llmSpecific":true,"classifierConfidence":0.92,"researchCategory":null,"atlasIds":null}}