Security Flaw in NVIDIA's NemoClaw Could Let Hackers Hijack Local AI Models
Security researchers at Oasis Security have discovered a weakness in NVIDIA's NemoClaw tool that could allow an attacker-controlled webpage to take unauthenticated control of a local Ollama instance used to run AI agents. Once compromised, the attacker could plant hidden instructions inside the AI model itself, potentially altering how it responds or behaves without the user's knowledge.
This type of attack is concerning because it doesn't require the victim to download a malicious file or click a suspicious link in the traditional sense—simply visiting a compromised or malicious webpage while running the vulnerable setup could be enough to trigger the exploit. The researchers shared their findings with NVIDIA's Product Security Incident Response Team before going public, following standard responsible disclosure practices.
As more businesses begin experimenting with local AI tools to keep data in-house and reduce cloud costs, this incident is a reminder that these systems can introduce new and unfamiliar attack surfaces. Any exposed local service, including AI infrastructure, needs to be properly secured and kept up to date, just like any other software running on a business network.