返回新聞
安全性AI Understanding 簡報

GBHackers 報告嚴重的 NVIDIA NemoClaw 缺陷可能會讓攻擊者持續劫持本地 AI 代理

GBHackers 報告稱,CVE-2026-65105 可能會將 NemoClaw 的本地 Ollama API 暴露給 DNS 重新綁定和持久模型模板中毒。 NVIDIA的回應在此並未獲得獨立證實。

5 min readRead the linked source
Source-provided image accompanying GBHackers reports critical NVIDIA NemoClaw flaw could let attackers persistently hijack local AI agents
來源參考來源記錄
出版商
gbhackers.com
來源連結
gbhackers.comhttps://gbhackers.com/nvidia-nemoclaw-vulnerability/
來源類型
連結來源-主要來源狀態尚未確定。
背景60 秒內了解這一點

從這裡開始

關鍵術語

API(應用程式介面)
一種軟體系統向另一個系統發送請求並接收回應的結構化方式。
MCP(模型上下文協定)
一種開放協議,允許人工智慧應用程式以標準方式連接到外部工具、資料來源和上下文提供者。
系統提示
為模型設定行為、策略和回應方式的高優先指令。
測試一下自己AI 代理測驗

發生了什麼事

GBHackers reports that researchers Elad Luz and Ofek Itach of Oasis Security identified CVE-2026-65105 in NVIDIA NemoClaw. The reported flaw involves NemoClaw configuring its local Ollama inference service to listen on all network interfaces, potentially allowing browser-based DNS rebinding attacks to reach an unauthenticated API.

GBHackers reports that Oasis Security researchers Elad Luz and Ofek Itach disclosed a vulnerability tracked as CVE-2026-65105 in NVIDIA NemoClaw. According to the report, NemoClaw can deploy the OpenClaw AI agent inside NVIDIA OpenShell sandboxes while using Ollama on the host as a local inference backend. The article says the vulnerable setup configures Ollama with OLLAMA_HOST=0.0.0.0:11434, which binds the service to all network interfaces rather than only the loopback address. GBHackers says users may be told the service is available at localhost:11434, even though the configuration also permits local-network access.

GBHackers reports that Ollama’s API on port 11434 does not require authentication and ordinarily relies on browser-origin checks, including CORS and Host-header validation. The researchers reportedly found that Host-header validation can be bypassed when Ollama is bound to a non-loopback address such as 0.0.0.0. In the attack described by the outlet, a victim visits an attacker-controlled domain that initially resolves to the attacker’s server. The domain is later changed to resolve to a local address, such as 127.0.0.1, while the browser continues treating the hostname as the same origin. The article says this can allow JavaScript from the malicious site to make requests to the victim’s local Ollama service.

According to GBHackers, the exposed API could let an attacker enumerate installed models, identify the Ollama version, submit inference requests, download large models, or delete existing models. The article identifies model-template poisoning as the most serious reported possibility. It says an attacker could retrieve a legitimate template through /api/show and use /api/create to preserve the model’s visible name, metadata, size, and apparent capabilities while adding hidden instructions to the way messages are processed. GBHackers reports that those instructions could persist across later interactions, potentially directing an agent to generate backdoored code, suppress warnings, recommend malicious packages or URLs, or exfiltrate data if the agent has outbound access. These findings have not been independently confirmed from the source material provided.

來源詳情: gbhackers.com ↗

為什麼這很重要

If the report’s technical account is accurate, an attacker could do more than consume local resources: they could alter a model’s chat template so hidden instructions persist across future interactions. The practical consequences would depend on the permissions and connected systems available to the AI agent.

The reported issue matters because it targets the boundary between a local AI model and the software that governs how an agent interprets messages. A conventional can sometimes be overridden or inspected as part of an application’s control logic. GBHackers says a poisoned chat template operates at a lower processing layer and is applied during every inference request, which could make the change harder for an ordinary user to notice. The article’s account therefore describes a persistence risk rather than a one-time malicious prompt.

The potential impact is shaped by what the agent can reach. GBHackers says OpenShell may reduce direct host-level exposure through filesystem, network, and process isolation, but it also emphasizes that the remaining risk depends on the agent’s granted permissions. The report lists source repositories, CI/CD systems, internal APIs, cloud platforms, messaging services, and Model Context Protocol servers as examples of connected resources. If a compromised agent can access such systems, hidden instructions could influence code generation, recommendations, data handling, or actions taken through those integrations. The source does not establish that any of these systems were actually compromised.

The reported 0.0.0.0 binding also creates a separate local-network concern. GBHackers says other devices on the same network segment could directly access the Ollama service without using DNS rebinding. That broadens the issue beyond a victim visiting a malicious webpage and makes network segmentation and service exposure relevant to deployment decisions. At the same time, the source does not provide evidence of exploitation in the wild, affected deployment counts, successful compromise of a real organization, or confirmed data theft. It also does not independently establish how every NemoClaw installation is configured.

Interactive Mechanism

互動機制:它實際上是如何運作的

以互動方式探索這項發展背後的基礎技術。

Agent Lifecycle Stage:
1
User Intent & Planning: "Audit customer refund request #4092 and settle payment."
2
Tool Calling: Emits structured JSON call crm_get_transaction(id='4092').
3
Guardrail & Verification:🛡️ Paused: High-value action requires human operator sign-off.
4
Final Settlement: Refund recorded, email receipt dispatched, and audit log stored.
Core takeaway: An AI agent is not just a language model—it is a closed loop of planning, tool invocation, and environment feedback. Production systems require self-healing retries and strict human approval guardrails.
互動式概念檢查+10 Points
AI Agents Quiz

An agent must create a draft calendar event for Tuesday at 2 p.m. Which evidence would establish the requested result?

接下來看什麼

NVIDIA’s response, any patch or configuration guidance, and independent technical validation are the key outstanding questions. Organizations using NemoClaw with Ollama should review port 11434 exposure, restrict access, and audit model templates for unauthorized changes.

The first issue to watch is whether NVIDIA confirms CVE-2026-65105 and publishes a patch, mitigation, or revised installation guidance. GBHackers says the researchers reported the issue to NVIDIA’s Product Security Incident Response Team before publication, but the supplied article does not include NVIDIA’s response or say whether a fix was available at publication. Until that information is available, the severity and remediation status should be treated as reported rather than independently verified.

Operators should review whether Ollama is bound to 0.0.0.0 or another non-loopback address, restrict access to port 11434, and check firewall rules for local-network exposure. GBHackers specifically recommends reviewing exposed interfaces and auditing model templates for unauthorized modifications. Administrators should also examine which files, repositories, credentials, APIs, cloud services, and MCP servers an agent can access, because the article says those permissions determine how far a model-level compromise could extend. These are defensive measures derived from the report, not evidence that an incident has occurred.

Independent reproduction is another important checkpoint. Security teams and researchers will need to establish whether the described DNS-rebinding path works across supported browsers, operating systems, NemoClaw versions, and Ollama configurations, and whether template changes persist exactly as reported. They should also determine how administrators can reliably detect altered templates and whether sandbox controls prevent access to sensitive resources. The supplied source does not state the affected version range, CVSS score, exploit code availability, patch timeline, or number of exposed installations, so those details remain meaningful unknowns.

相關指引和測驗

人工智慧代理人工智慧模型解釋人工智慧安全Prompt Engineering測試你所知道的—嘗試免費的人工智慧測驗在我們的詞彙表中尋找人工智慧術語關注AI監管追蹤器
覺得有用嗎?