Researchers at Oasis Security have disclosed a flaw in Nvidia’s NemoClaw that lets an attacker-controlled webpage take unauthenticated control of the Ollama server running a developer’s AI agent, and write hidden instructions into the model itself. The vulnerability is tracked as CVE-2026-65105. Oasis reported it to Nvidia’s product security team before publishing, and no exploitation has been observed.
NemoClaw is the runtime Nvidia released at GTC in March as a safer way to operate agents such as OpenClaw, placing the agent inside a sandbox that limits its reach into the file system, network and running processes. It can serve the agent’s model locally through Ollama rather than calling a cloud API. That local server is what an attacker ends up owning.
The opening is a bind address. Docker containers cannot reach 127.0.0.1, where Ollama listens by default, so NemoClaw starts it with OLLAMA_HOST=0.0.0.0:11434, exposing port 11434 on every network interface while the install message still reads localhost. Ollama’s API has no authentication of its own. Two middleware checks substitute for it: an origin allowlist and Host header validation. Oasis found the Host check is skipped whenever the bind address is not loopback, leaving only the origin allowlist, which DNS rebinding defeats. An attacker serves a page from a domain they control, then re-points that domain at 127.0.0.1. The browser’s same-origin policy keys on the hostname rather than the address behind it, and the requests land on the victim’s machine.
Injecting a system prompt would not survive, because OpenClaw sends its own and overrides it. So the researchers went lower. Ollama’s /api/create endpoint accepts a template field, a Go template that renders the message list into the raw text the model reads. An attacker can pull the existing template through /api/show, splice an instruction into it, and write it back. Every message the client sends afterward passes through the attacker’s version, including the agent’s own system prompt, which now arrives with the hidden instruction attached.
Nothing about the model looks wrong from outside. Name, size and metadata read normally, and opening a fresh conversation clears nothing, because the payload sits in the model definition rather than the conversation state. An instruction in that position can tell an agent to write vulnerabilities into code that passes casual review, stay quiet about security problems, or push conversation contents to an outside endpoint. Elad Luz, head of research at Oasis, said the change sits “one layer beneath anything a guardrail or an operator can see.”
The fix is partial. Version 0.0.35 closed the issue on macOS and Linux. Windows and WSL remain unfixed, with v0.0.34 adding a warning instead. Ollama itself hardened this same class of browser-to-local-service exposure back in 2024, under CVE-2024-28224.
Randolph Barr, chief information security officer at Cequence Security, said the technique is old and the target is what is new. “DNS rebinding’s been a browser party trick for over a decade, but pointing it at an unauthenticated local model server is the new part,” he said. “Sandboxing the agent doesn’t buy you much if the thing it’s built on top of is reachable from any tab in the browser.”
Agent-facing supply chains have been productive ground this year, from split instructions that doubled how often coding agents complied to a single email planting a persistent false memory in an assistant.
Sources: SiliconANGLE, The Hacker News
–
By the Control Plane Editorial Team