NVIDIA NemoClaw Flaw Enables AI Agent Hijack via DNS Rebinding
A critical vulnerability in NVIDIA's NemoClaw tool could allow an attacker to gain persistent control of a locally deployed AI agent through a single visit to a malicious website. The flaw, discovered by researchers from Oasis Security, enables the poisoning of an AI model's core instructions, creating a hidden backdoor that survives across conversations. The vulnerability, tracked as CVE-2026-65105, resides in how NemoClaw configures the Ollama inference backend. To allow communication between its Docker-based OpenShell sandboxes and the host, NemoClaw starts Ollama with the setting OLLAMA_HOST=0.0.0.0:11434.
Verilumia