vulnerability
Finding Nemo(Claw): Networking Issue Allows for LLM Poisoning in OpenClaw
High
Summary
A vulnerability in NVIDIA's NemoClaw tool, used for deploying AI agents with OpenClaw, allows unauthenticated attackers to poison a large language model's chat template and corrupt the AI agents using it. The issue stems from a misconfigured Ollama API that exposes the local model server to browser-based attacks via DNS rebinding. While NVIDIA has released a fix for MacOS and Linux, Windows users are currently without a patch. This represents a significant risk due to the potential for persistent manipulation of AI agent behavior and data exfiltration.
Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data
