AgentsAugust 25, 2026via SiliconAngle

Nvidia NemoClaw flaw let attackers poison the model behind a developer’s AI agent

Why it matters

A critical vulnerability in Nvidia's NemoClaw allows remote model poisoning via browser visit, exposing developers running local agent infrastructure to full compromise. This is the kind of supply-chain risk that changes how teams deploy agents.

Key signals

  • CVE-2026-65105 in Nvidia NemoClaw
  • Remote exploit: triggered by single malicious website visit
  • Impact: full control of local model server powering AI agents
  • Disclosed by Oasis Security Ltd. (nonhuman identity security company)
  • Vulnerability reported to Nvidia Product Security

The hook

CVE-2026-65105: One malicious website visit hands attackers full control of your AI agent's model server.

Researchers at nonhuman identity security company Oasis Security Ltd. today disclosed a vulnerability in Nvidia Corp.’s NemoClaw that hands an attacker full control of the local model server powering a developer’s AI agent. The vulnerability, tracked as CVE-2026-65105, can be triggered by one visit

The week's key stories, every Friday.

For practitioners and enthusiasts — free, in your inbox.

Free forever. No spam.