뉴스로 돌아가기
보안AI Understanding 브리핑

GBHackers는 심각한 NVIDIA NemoClaw 결함으로 인해 공격자가 로컬 AI 에이전트를 지속적으로 하이재킹할 수 있다고 보고했습니다.

GBHackers는 CVE-2026-65105가 NemoClaw의 로컬 Ollama API를 DNS 리바인딩 및 지속적인 모델 템플릿 중독에 노출시킬 수 있다고 보고했습니다. NVIDIA의 응답은 여기서 독립적으로 확인되지 않습니다.

5 min readRead the linked source
Source-provided image accompanying GBHackers reports critical NVIDIA NemoClaw flaw could let attackers persistently hijack local AI agents
소스 참조녹음된 소스
출판사
gbhackers.com
소스 링크
gbhackers.comhttps://gbhackers.com/nvidia-nemoclaw-vulnerability/
소스 유형
연결된 소스 — 기본 소스 상태가 설정되지 않았습니다.
맥락60초 안에 이해하세요

여기서 시작하세요

주요 용어

API(애플리케이션 프로그래밍 인터페이스)
한 소프트웨어 시스템이 다른 시스템에 요청을 보내고 응답을 받는 구조화된 방식입니다.
MCP(모델 컨텍스트 프로토콜)
AI 애플리케이션이 표준 방식으로 외부 도구, 데이터 소스 및 컨텍스트 제공자에 연결할 수 있게 해주는 개방형 프로토콜입니다.
시스템 프롬프트
모델의 동작, 정책 및 응답 스타일을 설정하는 우선순위가 높은 명령입니다.
자신을 테스트해 보세요AI 에이전트 퀴즈

무슨 일이 일어났나요?

GBHackers reports that researchers Elad Luz and Ofek Itach of Oasis Security identified CVE-2026-65105 in NVIDIA NemoClaw. The reported flaw involves NemoClaw configuring its local Ollama inference service to listen on all network interfaces, potentially allowing browser-based DNS rebinding attacks to reach an unauthenticated API.

GBHackers reports that Oasis Security researchers Elad Luz and Ofek Itach disclosed a vulnerability tracked as CVE-2026-65105 in NVIDIA NemoClaw. According to the report, NemoClaw can deploy the OpenClaw AI agent inside NVIDIA OpenShell sandboxes while using Ollama on the host as a local inference backend. The article says the vulnerable setup configures Ollama with OLLAMA_HOST=0.0.0.0:11434, which binds the service to all network interfaces rather than only the loopback address. GBHackers says users may be told the service is available at localhost:11434, even though the configuration also permits local-network access.

GBHackers reports that Ollama’s API on port 11434 does not require authentication and ordinarily relies on browser-origin checks, including CORS and Host-header validation. The researchers reportedly found that Host-header validation can be bypassed when Ollama is bound to a non-loopback address such as 0.0.0.0. In the attack described by the outlet, a victim visits an attacker-controlled domain that initially resolves to the attacker’s server. The domain is later changed to resolve to a local address, such as 127.0.0.1, while the browser continues treating the hostname as the same origin. The article says this can allow JavaScript from the malicious site to make requests to the victim’s local Ollama service.

According to GBHackers, the exposed API could let an attacker enumerate installed models, identify the Ollama version, submit inference requests, download large models, or delete existing models. The article identifies model-template poisoning as the most serious reported possibility. It says an attacker could retrieve a legitimate template through /api/show and use /api/create to preserve the model’s visible name, metadata, size, and apparent capabilities while adding hidden instructions to the way messages are processed. GBHackers reports that those instructions could persist across later interactions, potentially directing an agent to generate backdoored code, suppress warnings, recommend malicious packages or URLs, or exfiltrate data if the agent has outbound access. These findings have not been independently confirmed from the source material provided.

소스 세부정보: gbhackers.com ↗

왜 중요한가요?

If the report’s technical account is accurate, an attacker could do more than consume local resources: they could alter a model’s chat template so hidden instructions persist across future interactions. The practical consequences would depend on the permissions and connected systems available to the AI agent.

The reported issue matters because it targets the boundary between a local AI model and the software that governs how an agent interprets messages. A conventional can sometimes be overridden or inspected as part of an application’s control logic. GBHackers says a poisoned chat template operates at a lower processing layer and is applied during every inference request, which could make the change harder for an ordinary user to notice. The article’s account therefore describes a persistence risk rather than a one-time malicious prompt.

The potential impact is shaped by what the agent can reach. GBHackers says OpenShell may reduce direct host-level exposure through filesystem, network, and process isolation, but it also emphasizes that the remaining risk depends on the agent’s granted permissions. The report lists source repositories, CI/CD systems, internal APIs, cloud platforms, messaging services, and Model Context Protocol servers as examples of connected resources. If a compromised agent can access such systems, hidden instructions could influence code generation, recommendations, data handling, or actions taken through those integrations. The source does not establish that any of these systems were actually compromised.

The reported 0.0.0.0 binding also creates a separate local-network concern. GBHackers says other devices on the same network segment could directly access the Ollama service without using DNS rebinding. That broadens the issue beyond a victim visiting a malicious webpage and makes network segmentation and service exposure relevant to deployment decisions. At the same time, the source does not provide evidence of exploitation in the wild, affected deployment counts, successful compromise of a real organization, or confirmed data theft. It also does not independently establish how every NemoClaw installation is configured.

Interactive Mechanism

대화형 메커니즘: 실제로 작동하는 방식

이 개발의 이면에 있는 기본 기술을 대화식으로 살펴보세요.

Agent Lifecycle Stage:
1
User Intent & Planning: "Audit customer refund request #4092 and settle payment."
2
Tool Calling: Emits structured JSON call crm_get_transaction(id='4092').
3
Guardrail & Verification:🛡️ Paused: High-value action requires human operator sign-off.
4
Final Settlement: Refund recorded, email receipt dispatched, and audit log stored.
Core takeaway: An AI agent is not just a language model—it is a closed loop of planning, tool invocation, and environment feedback. Production systems require self-healing retries and strict human approval guardrails.
대화형 개념 확인+10 Points
AI Agents Quiz

An agent must create a draft calendar event for Tuesday at 2 p.m. Which evidence would establish the requested result?

다음에 무엇을 볼 것인가

NVIDIA’s response, any patch or configuration guidance, and independent technical validation are the key outstanding questions. Organizations using NemoClaw with Ollama should review port 11434 exposure, restrict access, and audit model templates for unauthorized changes.

The first issue to watch is whether NVIDIA confirms CVE-2026-65105 and publishes a patch, mitigation, or revised installation guidance. GBHackers says the researchers reported the issue to NVIDIA’s Product Security Incident Response Team before publication, but the supplied article does not include NVIDIA’s response or say whether a fix was available at publication. Until that information is available, the severity and remediation status should be treated as reported rather than independently verified.

Operators should review whether Ollama is bound to 0.0.0.0 or another non-loopback address, restrict access to port 11434, and check firewall rules for local-network exposure. GBHackers specifically recommends reviewing exposed interfaces and auditing model templates for unauthorized modifications. Administrators should also examine which files, repositories, credentials, APIs, cloud services, and MCP servers an agent can access, because the article says those permissions determine how far a model-level compromise could extend. These are defensive measures derived from the report, not evidence that an incident has occurred.

Independent reproduction is another important checkpoint. Security teams and researchers will need to establish whether the described DNS-rebinding path works across supported browsers, operating systems, NemoClaw versions, and Ollama configurations, and whether template changes persist exactly as reported. They should also determine how administrators can reliably detect altered templates and whether sandbox controls prevent access to sensitive resources. The supplied source does not state the affected version range, CVSS score, exploit code availability, patch timeline, or number of exposed installations, so those details remain meaningful unknowns.

관련 가이드 및 퀴즈

AI 에이전트AI 모델 설명AI 안전Prompt Engineering알고 있는 내용을 테스트해 보세요. 무료 AI 퀴즈를 시도해 보세요.용어집에서 AI 용어를 찾아보세요.AI 규제 추적기를 따르세요
이것이 유용하다고 생각하시나요?