NVIDIA NemoClaw exposed a local model server, letting a webpage persistently poison the agent's model template (CVE-2026-65105)
2026-nemoclaw-ollama-template-poisoning · 2026-08-25
NVIDIA's NemoClaw deployment wrapper bound its local Ollama instance to all interfaces without authentication. Via DNS rebinding, a single malicious webpage could reach the API and rewrite the model's chat template (CVE-2026-65105) — a structural, persistent poisoning applied to every message that could make the agent supply vulnerable code, suppress warnings, or exfiltrate data. Disclosed by Oasis Security; patched by NVIDIA.
System
- Framework
- NVIDIA NemoClaw (deployment wrapper for the OpenClaw agent)
- Tools
- ollama, browser
- Vendor
- NVIDIA
- Autonomy
- supervised-autonomous
Classification
- Primary class
- memory-context-poisoning
- Chain
- memory-context-poisoning/memory-injection → insecure-output/injection-vuln
- Attack vector
- untrusted-content
- Causation
- entity: human · intentionality: intentional · timing: post-deployment
Trigger
NemoClaw launched Ollama with OLLAMA_HOST=0.0.0.0:11434, exposing the unauthenticated model API on all interfaces and disabling Ollama's Host-header validation. A malicious webpage used DNS rebinding to reach the local API and called /api/create to rewrite the model's chat template, appending hidden attacker instructions applied at inference time to every message — including the client's own system prompt.
Root cause
A local model server was bound to all interfaces without authentication and with Host-header validation disabled, so a browser-based DNS-rebinding attack could reach it. The chat-template mechanism then allowed structural, persistent poisoning — distinct from per-query prompt injection because it survives across sessions and overrides the client's system prompt.
Contributing factors
- Ollama was bound to 0.0.0.0 without authentication, reachable beyond loopback.
- Binding to all interfaces disabled Ollama's Host-header validation, enabling DNS rebinding.
- The model template is applied to all messages, so poisoning it persists and overrides system prompts.
Detection
Discovered by Oasis Security during research into non-human identity and AI agent risks; responsibly reported to NVIDIA's PSIRT before publication on 2026-08-25.
Recovery
NVIDIA rated it High (CVSS 8.1) and patched it; NemoClaw v0.0.35 fixed macOS and Linux (Linux versions 0 through 0.0.25 affected), with Windows/WSL reported still unfixed at disclosure.
Prevention
Bind local model servers to loopback and require authentication; keep Host-header/origin validation enabled to resist DNS rebinding; treat the model template/config as security-critical and disallow unauthenticated modification; isolate agent-reachable local services.
Blast radius
- Data
- A poisoned template could direct the agent to supply vulnerable code, suppress security warnings, or exfiltrate data, and could reach source control, cloud accounts, and other resources the agent is authorized to use. confidential
- User harm
- A responsibly disclosed vulnerability demonstrated as a proof of concept; no confirmed in-the-wild exploitation was reported. none-reported
- Scope
- NemoClaw for Linux 0–0.0.25 (Windows/WSL still unfixed at disclosure)
- Reversibility
- partially-reversible
References
- CWE
- CWE-346
- OWASP LLM
- LLM04 LLM05
- Tags
- model-poisoning dns-rebinding ollama nemoclaw drive-by cve
Sources
Cite this incident
Permalink: https://swarmproof.github.io/agent-postmortems/2026-nemoclaw-ollama-template-poisoning/
@misc{2026-nemoclaw-ollama-template-poisoning,
title = {NVIDIA NemoClaw exposed a local model server, letting a webpage persistently poison the agent's model template (CVE-2026-65105)},
year = {2026},
howpublished = {agent-postmortems},
url = {https://swarmproof.github.io/agent-postmortems/2026-nemoclaw-ollama-template-poisoning/}
}