AgentsAugust 25, 2026via SiliconAngle
Nvidia NemoClaw flaw let attackers poison the model behind a developer’s AI agent
Why it matters
A critical vulnerability in Nvidia's NemoClaw allows remote model poisoning via browser visit, exposing developers running local agent infrastructure to full compromise. This is the kind of supply-chain risk that changes how teams deploy agents.
Key signals
- CVE-2026-65105 in Nvidia NemoClaw
- Remote exploit: triggered by single malicious website visit
- Impact: full control of local model server powering AI agents
- Disclosed by Oasis Security Ltd. (nonhuman identity security company)
- Vulnerability reported to Nvidia Product Security
The hook
CVE-2026-65105: One malicious website visit hands attackers full control of your AI agent's model server.
Researchers at nonhuman identity security company Oasis Security Ltd. today disclosed a vulnerability in Nvidia Corp.’s NemoClaw that hands an attacker full control of the local model server powering a developer’s AI agent. The vulnerability, tracked as CVE-2026-65105, can be triggered by one visit …