One Malicious Webpage Can Now Silently Poison Your Local AI Agent: Inside NVIDIA NemoClaw's CVE-2026-65105
Oasis Security details CVE-2026-65105: NemoClaw binds Ollama to 0.0.0.0:11434 with no auth, so a DNS-rebinding webpage can rewrite the model's chat template and steer a developer's AI agent persistently, invisibly, from the browser.
The scariest AI security disclosure this month is not about a frontier model escaping its alignment training. It is about a network flag. On August 25, Oasis Security — the non-human-identity firm that Cyera agreed to acquire for a reported $1 billion in July — published details of CVE-2026-65105, a flaw in NVIDIA’s NemoClaw that lets a single visit to a malicious webpage hand an attacker full, unauthenticated control over the local model server powering a developer’s AI agent, and silently plant instructions inside the model that survive reboots, fresh chats, and even the agent’s own system prompt.
What NemoClaw is, and why the flag matters
NemoClaw is NVIDIA’s tool — introduced at GTC in March 2026 — for running the open-source OpenClaw AI agent inside an OpenShell sandbox. The sandbox fences off the filesystem, network, and processes the agent can touch. Crucially, NemoClaw supports local inference via Ollama: instead of shipping code and prompts to a cloud API, the model runs on the developer’s own hardware. It is a privacy-first design, and on paper exactly what enterprises say they want from agentic AI.
The problem is in the plumbing. OpenShell runs its sandboxes inside Docker containers, and Docker containers have no route to 127.0.0.1 on the host — which is where Ollama binds by default. NemoClaw’s fix is to launch Ollama with OLLAMA_HOST=0.0.0.0:11434, exposing port 11434 on every network interface. Meanwhile, the installer still tells the user the perfectly comforting words: “Using Ollama on localhost:11434.”
That gap — between what the developer believes (“local means private”) and what the socket actually does (reachable by anything on the network segment) — is the entire vulnerability.
The attack chain: browser to poisoned model
Ollama’s API has no authentication. Two middleware checks stand in as substitutes: an origin allowlist and Host header validation. Oasis found that the Host check is skipped entirely whenever the bind address is not loopback — precisely the configuration NemoClaw creates. That leaves the origin check, and a classic DNS rebinding attack walks straight around it:
- The attacker points a domain they control at their own server and serves the victim a page from port 11434.
- The domain then re-resolves to
127.0.0.1. Because the browser’s same-origin policy keys on the hostname, not the IP behind it, the browser raises no objection. - JavaScript on the page now talks to the Ollama instance running on the victim’s machine — full API access, zero authentication, zero clicks beyond the initial visit.
With the API in hand, an attacker can enumerate installed models, lift the machine’s hostname and public key, or delete models outright. But the truly nasty move is persistent model poisoning.
A hidden system prompt injected via the obvious route does not survive — OpenClaw sends its own system prompt, which overrides anything baked in. So Oasis went one layer lower. Ollama’s /api/create endpoint accepts a template field: a Go template that renders the entire message list into the raw text the model actually reads. The attacker pulls the model’s existing template via /api/show, splices an instruction into it, and writes it back. From that moment, every message the client sends — including the agent’s own system prompt — reaches the model with the attacker’s instruction appended.
Why this is so hard to detect
Nothing on the surface looks wrong. Model name, size, and metadata all read as normal. Opening a fresh chat clears nothing, because the payload lives in the model definition, far below the conversation state an operator can reset. Elad Luz, head of research at Oasis, put it precisely: the change sits “one layer beneath anything a guardrail or an operator can see,” turning a misconfiguration into an integrity problem.
And the sandbox — the thing NemoClaw exists to provide — does not help. “The blast radius of an AI system is its authorizations rather than its isolation,” Luz noted. An instruction planted in the template can direct the agent to write subtle vulnerabilities into code that passes casual review, stay quiet about security problems it encounters, or exfiltrate conversation contents to an outside endpoint.
Fix status and what to do now
NemoClaw v0.0.35 patches the issue on macOS and Linux; Windows/WSL remains unfixed at time of writing. NVIDIA was notified through its PSIRT before publication. Commenting on the report, Black Duck’s Collin Hogue-Spears noted that Ollama itself hardened this class of browser-to-local-service exposure back in 2024 under CVE-2024-28224, and that NemoClaw’s current design refuses a non-loopback Ollama backend on covered topologies. His advice for anyone on the older pattern is the checklist worth taping to your monitor:
- Keep Ollama bound to loopback, behind an authenticated proxy.
- Validate the
Hostheader against an allowlist. - Audit model templates (
/api/show) for unexpected edits.
His summary line deserves to become an industry aphorism: “Local describes where the model runs. Private describes who can reach it.”
The bigger picture: agentic risk lives in the plumbing
Cequence Security CISO Randolph Barr’s commentary nailed why this disclosure matters beyond one CVE: DNS rebinding “has been a browser party trick for over a decade, but pointing it at an unauthenticated local model server is the new part — and it’s a good preview of where agentic AI risk actually lives. It’s not really in the model; it’s in the plumbing around it.”
That is the lesson for anyone building or deploying local AI agents in 2026. The industry’s security attention has focused on jailbreaks, prompt injection, and alignment — the model layer. CVE-2026-65105 shows that as agents gain filesystem access, shell execution, and multi-hour autonomy, a misconfigured bind address becomes a persistent-compromise primitive. The same day this dropped, Cisco Talos was documenting a Chinese-linked crew using AI coding assistants to scale intrusions against 170,000 servers, and EPA was moving to streamline air permits for the diesel generators backing AI data centers. The attack surface of “AI” is expanding in every direction at once — and the least glamorous corners, like a localhost port with no authentication, are where the real incidents will come from.
For developers running Ollama, NemoClaw, or any local inference server: check your bind address today. If it says 0.0.0.0 and you did not deliberately put an authenticated proxy in front of it, assume the template layer of your models is attacker-writable — and rebuild from a known-good source.
Sources
- [1] https://www.cyera.com/research/nemoclaw-one-website-visit-to-hijack-your-ai-agent
- [2] https://siliconangle.com/2026/08/25/nvidia-nemoclaw-flaw-let-attackers-poison-the-model-behind-a-developers-ai-agent/
- [3] https://thehackernews.com/2026/08/25/nvidia-nemoclaw-cve-2026-65105.html
- [4] https://forkast.news/nemoclaws-deployment-wrapper-exposed-local-ai-agents-to-drive-by-hijacking-and-persistent-model-poisoning/
- [5] https://hackread.com/nvidia-nemoclaw-flaw-hijack-openclaw-ai-agents/