news.mlab.sh
Back to the feed
vulnerability

A Malicious Webpage Could Poison Your Local AI Model Behind NVIDIA NemoClaw

High
Image: The Hacker News
Summary

A vulnerability in NVIDIA NemoClaw allows an attacker to poison an AI model by serving a malicious webpage that can inject hidden instructions into every conversation. The vulnerability stems from a misconfigured Ollama backend that exposes the API to all network interfaces, bypassing authentication and allowing an attacker to modify the model's chat template. While NVIDIA has released a fix, the vulnerability remains unpatched for many installations. The issue was previously identified and exploited against Paperclip, demonstrating a similar technique.

Read the full article at The Hacker News

Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data

Report an error
Confirmed errors are fixed and listed on /corrections.