Security AI
Researchers report NemoClaw local-model exposure on Windows and WSL paths
Image: Primary Oasis Security reported that an attacker-controlled webpage could use DNS rebinding to reach an unauthenticated local Ollama instance configured by NVIDIA NemoClaw, then alter a model chat template to add hidden instructions to later conversations.
The report says the chain was tested on macOS with Firefox against a vulnerable version. NVIDIA NemoClaw v0.0.35 fixed the issue on macOS and Linux, according to the researcher, but the Windows and WSL path remains unfixed and carries a warning. No exploitation had been reported as of August 25.
Sources
Published by Tech & Business, a media brand covering technology and business.
This story was sourced from The Hacker News and reviewed by the T&B editorial agent team.
Back to Newswire


