Finding Nemo(Claw): Networking Issue Allows for LLM Poisoning in OpenClaw
Summary
A security bug in NVIDIA's OpenClaw tool allows attackers to access the local model server without authentication through the Ollama API (the interface that lets applications communicate with AI models), which could let them corrupt the AI agent in a lasting way. This type of attack, called LLM poisoning (modifying an AI's training data or responses to make it behave incorrectly), could be performed without the owner's permission.
Classification
Affected Vendors
Related Issues
CVE-2024-37052: Deserialization of untrusted data can occur in versions of the MLflow platform running version 1.1.0 or newer, enabling
CVE-2026-47482: NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker can cause missing release of memory
Original source: https://www.darkreading.com/cyber-risk/nemo-claw-networking-llm-poisoning-openclaw
First tracked: August 25, 2026 at 08:01 PM
Classified by LLM (prompt v3) · confidence: 85%