NemoClaw’s Deployment Wrapper Exposed Local AI Agents to Drive-By Hijacking and Persistent Model Poisoning
A vulnerability in NVIDIA’s NemoClaw, the deployment wrapper for the OpenClaw AI agent ecosystem, demonstrates how configuration choices in agent infrastructure can create attack surfaces that bypass traditional security controls entirely. Research published August 25 by Cyera details CVE-2026-65105 — a flaw that lets an attacker hijack a local AI agent with a single website…