Researchers Warn a Booby-Trapped Webpage Could Hijack NVIDIA NemoClaw AI Agents
Oasis Security says a flaw in NVIDIA's NemoClaw lets a malicious site quietly take over a local AI model and slip in hidden instructions.

Key points
- Oasis Security disclosed a weakness in NVIDIA NemoClaw that lets a malicious webpage silently seize control of the local AI engine powering an agent.
- The attack needs no login or password and can plant hidden instructions inside the AI model itself.
- Oasis Security reported the issue to NVIDIA's Product Security Incident Response Team before going public.
- The finding was shared with The Hacker News ahead of publication.
- Users of local AI agents built on NemoClaw and Ollama should treat the risk as active until NVIDIA issues a fix.
Security researchers at Oasis Security say a flaw in NVIDIA NemoClaw, a framework for building AI agents that run on a user's own machine, could let a booby-trapped webpage take over the AI engine sitting on that computer. No password required. Just a visit to the wrong site.
The target underneath is Ollama, a popular tool that runs large language models locally on a laptop or workstation. NemoClaw relies on Ollama to power its agent. Oasis Security says a webpage the victim opens in a normal browser can reach that local Ollama service directly, without authentication, and issue commands to it.
Worse, the researchers say an attacker can use that access to plant hidden instructions inside the AI model itself. The model then carries those instructions into future conversations, even ones the user starts hours or days later. Oasis Security, which Cyera agreed to acquire for $1 billion in July, has been on our radar since that deal closed; this finding shows its research arm still has teeth.
What is NemoClaw, in plain English?
NemoClaw is NVIDIA software developers use to build AI assistants that run on your own computer rather than in the cloud. It's scaffolding around a local chatbot, leaning on Ollama, a separate program that actually loads and runs the AI model in the background.
When you talk to the agent, NemoClaw passes your message to Ollama and returns a reply. That plumbing normally sits quietly on your machine and listens only to local programs.
How does the attack work?
A malicious webpage, loaded in the victim's own browser, contacts the local Ollama service and issues commands as if it were a trusted local program. Oasis Security describes the service as reachable without authentication, so no login step stands in the way.
Once inside, an attacker can push instructions that get baked into the local model. The researchers frame this as poisoning the model: the AI keeps obeying the hidden guidance long after the malicious tab is closed.
For an ordinary user, that could mean an AI assistant that starts steering answers or leaking data typed into it, with no visible sign that anything changed. It's a close cousin to the one-click hijack we covered against Anthropic's Claude on 15 July 2026, but this variant targets a model running entirely on your own hardware.
Should users of local AI tools be worried?
If you run a local AI agent built on NemoClaw and Ollama, treat the risk as live until NVIDIA publishes a fix. Oasis Security went through NVIDIA's PSIRT process, so a formal advisory and CVE identifier are the next things to watch for.
The wider point is easy to miss. Local AI tools feel private because the model sits on your own hardware. But if the service running that model listens without a password, any webpage your browser loads can potentially talk to it.
A few sensible steps while a patch is pending:
- Avoid running local AI services on machines you use for general web browsing.
- Update NemoClaw and Ollama the moment fixes land.
- Restrict which programs can reach the local Ollama port using your operating system's firewall.
- Watch for odd behaviour from your local AI assistant, especially sudden shifts in the answers it gives.



