agent-postmortems a structured database of real AI-agent failures

← all incidents

hazard high confidence: confirmed status: final

NVIDIA NemoClaw exposed a local model server, letting a webpage persistently poison the agent's model template (CVE-2026-65105)

2026-nemoclaw-ollama-template-poisoning · 2026-08-25

NVIDIA's NemoClaw deployment wrapper bound its local Ollama instance to all interfaces without authentication. Via DNS rebinding, a single malicious webpage could reach the API and rewrite the model's chat template (CVE-2026-65105) — a structural, persistent poisoning applied to every message that could make the agent supply vulnerable code, suppress warnings, or exfiltrate data. Disclosed by Oasis Security; patched by NVIDIA.

System

Framework
NVIDIA NemoClaw (deployment wrapper for the OpenClaw agent)
Tools
ollama, browser
Vendor
NVIDIA
Autonomy
supervised-autonomous

Classification

Primary class
memory-context-poisoning
Chain
memory-context-poisoning/memory-injection → insecure-output/injection-vuln
Attack vector
untrusted-content
Causation
entity: human · intentionality: intentional · timing: post-deployment

Trigger

NemoClaw launched Ollama with OLLAMA_HOST=0.0.0.0:11434, exposing the unauthenticated model API on all interfaces and disabling Ollama's Host-header validation. A malicious webpage used DNS rebinding to reach the local API and called /api/create to rewrite the model's chat template, appending hidden attacker instructions applied at inference time to every message — including the client's own system prompt.

Root cause

A local model server was bound to all interfaces without authentication and with Host-header validation disabled, so a browser-based DNS-rebinding attack could reach it. The chat-template mechanism then allowed structural, persistent poisoning — distinct from per-query prompt injection because it survives across sessions and overrides the client's system prompt.

Contributing factors

  • Ollama was bound to 0.0.0.0 without authentication, reachable beyond loopback.
  • Binding to all interfaces disabled Ollama's Host-header validation, enabling DNS rebinding.
  • The model template is applied to all messages, so poisoning it persists and overrides system prompts.

Detection

Discovered by Oasis Security during research into non-human identity and AI agent risks; responsibly reported to NVIDIA's PSIRT before publication on 2026-08-25.

Recovery

NVIDIA rated it High (CVSS 8.1) and patched it; NemoClaw v0.0.35 fixed macOS and Linux (Linux versions 0 through 0.0.25 affected), with Windows/WSL reported still unfixed at disclosure.

Prevention

Bind local model servers to loopback and require authentication; keep Host-header/origin validation enabled to resist DNS rebinding; treat the model template/config as security-critical and disallow unauthenticated modification; isolate agent-reachable local services.

Blast radius

Data
A poisoned template could direct the agent to supply vulnerable code, suppress security warnings, or exfiltrate data, and could reach source control, cloud accounts, and other resources the agent is authorized to use. confidential
User harm
A responsibly disclosed vulnerability demonstrated as a proof of concept; no confirmed in-the-wild exploitation was reported. none-reported
Scope
NemoClaw for Linux 0–0.0.25 (Windows/WSL still unfixed at disclosure)
Reversibility
partially-reversible

References

CWE
CWE-346
OWASP LLM
LLM04 LLM05
Tags
model-poisoning dns-rebinding ollama nemoclaw drive-by cve

Sources

Cite this incident

@misc{2026-nemoclaw-ollama-template-poisoning,
  title = {NVIDIA NemoClaw exposed a local model server, letting a webpage persistently poison the agent's model template (CVE-2026-65105)},
  year = {2026},
  howpublished = {agent-postmortems},
  url = {https://swarmproof.github.io/agent-postmortems/2026-nemoclaw-ollama-template-poisoning/}
}