Malicious Webpage Exploits NVIDIA NemoClaw Weakness

A malicious webpage can potentially take control of a local AI model serving an Ollama instance, exploiting a weakness in NVIDIA NemoClaw, according to Oasis Security.

Bottom line: A single malicious webpage could compromise the integrity of a local AI model, leading to unauthorized access and data tampering.

What's happening: Oasis Security reported a vulnerability in NVIDIA NemoClaw, allowing an attacker-controlled webpage to take control of a local Ollama instance, which serves an AI agent. This instance is used by Google Cloud customers, including a major tech firm. The vulnerability exists in the NemoClaw version 3.5.1.

What to do: Security leaders should immediately update their NemoClaw version to 3.5.2 or higher, and monitor their Ollama instances for any suspicious activity, particularly if they are using an untrusted or compromised network.

Source: The Hacker News