NVIDIA NemoClaw의 취약점이 발견되어 악성 웹페이지가 AI 모델을 조작할 수 있는 가능성이 보고되었다.
Oasis Security는 NVIDIA NemoClaw의 취약점을 공개하며, 공격자가 제어하는 웹페이지가 인증 없이 로컬 Ollama 인스턴스를 제어하고 AI 모델에 숨겨진 명령을 심을 수 있다고 경고했다. 이 보고서는 The Hacker News와 공유되었으며, Oasis Security는 NVIDIA의 제품 보안 사고 대응 팀에 이러한 문제를 보고했다.
A vulnerability in NVIDIA NemoClaw allows a malicious webpage to take control of local AI models.
Oasis Security has disclosed a weakness in NVIDIA NemoClaw that could enable an attacker-controlled webpage to take unauthenticated control of the local Ollama instance serving an AI agent and embed hidden instructions within the model. This finding was shared with The Hacker News ahead of publication, and Oasis Security reported this issue to NVIDIA's Product Security Incident team.