NemoClaw’s AI can be poisoned through a browser tab
Summary
A vulnerability in Nvidia's NemoClaw allows attackers to poison a local AI model through a malicious website visit using DNS rebinding (a technique where an attacker tricks a browser into connecting to a local service by redirecting a domain name). Once the attacker gains access to the Ollama model server (the software that runs AI models locally), they can inject harmful instructions into the model's chat template (the layer controlling how messages are formatted), and these malicious instructions persist invisibly across all future conversations, making them extremely difficult to detect.
Solution / Mitigation
The flaw has been patched by Nvidia for non-Windows systems.
Classification
Affected Vendors
Related Issues
CVE-2024-37052: Deserialization of untrusted data can occur in versions of the MLflow platform running version 1.1.0 or newer, enabling
CVE-2026-47482: NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker can cause missing release of memory
Original source: https://www.csoonline.com/article/4214156/nemoclaws-ai-can-be-poisoned-through-a-browser-tab.html
First tracked: August 26, 2026 at 08:01 AM
Classified by LLM (prompt v3) · confidence: 92%