NVIDIA NemoClaw Flaw Lets Malicious Webpages Poison Local AI Models via Ollama
Oasis Security has disclosed a vulnerability in NVIDIA's NemoClaw, an open-source reference stack for running AI agents, that could allow an attacker-controlled…
Oasis Security has disclosed a vulnerability in NVIDIA's NemoClaw, an open-source reference stack for running AI agents, that could allow an attacker-controlled…
Two critical vulnerabilities in Paperclip, an open-source control plane for AI agents, could allow attackers to execute arbitrary commands on a server…
A high-severity flaw in Paperclip's local_trusted mode allows DNS rebinding attacks to execute commands on the developer's machine with CVSS 9.6. Fixed…
Multiple API routes in Paperclip lacked proper access checks, exposing sensitive data and control-plane details. Fixed in v2026.416.0 with added authentication and…
Paperclip is an AI model that Oasis Security demonstrated could be poisoned via chat template manipulation, similar to the NemoClaw vulnerability. The…