Nvidia NemoClaw flaw let attackers poison the model behind a developer’s AI agent
Researchers at nonhuman identity security company Oasis Security Ltd. today disclosed a vulnerability in Nvidia Corp.’s NemoClaw that hands an attacker full control of the local model server powering a developer’s AI agent.
The vulnerability, tracked as CVE-2026-65105, can be triggered by one visit to a malicious website. Oasis reported it to Nvidia’s Product Security Incident Response Team before publishing. The research is also the first from the team since Cyera Inc. agreed in July to buy Oasis for a reported $1 billion.
Nvidia released NemoClaw at its GTC conference in March as a safer way to run agents such as OpenClaw. The agent sits inside an OpenShell sandbox, which fences off the file system, the network and the processes it can touch.
NemoClaw can run the agent’s model locally through Ollama instead of calling out to a cloud service. Ollama is the server an attacker ends up controlling. Reaching it from inside the sandbox takes some work.








