Oasis Security researchers disclosed that NVIDIA NemoClaw can expose the local Ollama API on affected Windows and WSL installations by configuring OLLAMA_HOST=0.0.0.0:11434. An attacker-controlled webpage can exploit this exposure through DNS rebinding to bypass browser protections and access the unauthenticated model server after a victim visits the site. The attacker could enumerate, run, modify, or delete local models and alter a model's chat template with hidden instructions that persist across future OpenClaw agent conversations.
Persistent prompt poisoning could cause agents with sufficient permissions to generate backdoored code, weaken security controls, or exfiltrate data while concealing the malicious instructions from users. NVIDIA fixed the Ollama exposure in NemoClaw v0.0.35 for macOS and Linux; Windows and WSL remained without a full fix, although v0.0.34 added a warning. Separately, NVIDIA NemoClaw for Linux is affected by high-severity installation-process arbitrary code execution vulnerability CVE-2026-65081 (CVSS 8.1), for which organizations should apply NVIDIA updates and use hardened installation practices. No exploitation of the model-poisoning flaw had been observed.

Track how attackers are adapting to this technology.
9 events from the most recent confirmed update back to the earliest known activity.
NVIDIA published Security Bulletin 5872, “NVIDIA NemoClaw and OpenShell - August 2026,” listing 19 CVEs, including CVE-2026-65081 and CVE-2026-65082 through CVE-2026-65093, CVE-2026-65096 through CVE-2026-65099, and CVE-2026-65105. The available repository listing provides no vulnerability descriptions, severity ratings, affected versions, exploitation status, or remediation details.
A review of the NemoClaw repository found that version 0.0.106 introduced a default proxy check that refuses to start when its Ollama backend is bound to a non-loopback interface.
NCC Group published an advisory for Ollama's CVE-2024-28224 DNS rebinding vulnerability in the month following Ollama's March 2024 fix.
Ollama released version 0.1.29 with a fix for the previously documented DNS rebinding issue tracked as CVE-2024-28224.
Cyera detailed CVE-2026-65105 as a critical NemoClaw configuration vulnerability in which `OLLAMA_HOST=0.0.0.0:11434` can expose Ollama's unauthenticated API to DNS-rebinding attacks. Attackers could persistently poison model templates and thereby influence subsequent AI-agent interactions.
NVIDIA addressed the NemoClaw Ollama exposure issue for macOS and Linux in NemoClaw version 0.0.35. A corresponding fix for the Windows and WSL path was not available in the referenced reporting.
NemoClaw version 0.0.34 added a Windows installation path warning rather than correcting the exposed Ollama configuration on Windows and WSL.
Oasis Security/Cyera's Oasis Identity Research responsibly reported a NemoClaw configuration flaw to NVIDIA's Product Security Incident Response Team. The issue exposed an unauthenticated Ollama API to DNS-rebinding attacks that could allow persistent poisoning of model chat templates.
CVE-2026-65081 was identified as a high-severity, remotely exploitable arbitrary code execution vulnerability affecting the NVIDIA NemoClaw installation process on Linux. The flaw could execute untrusted code and potentially enable privilege escalation, data tampering, information disclosure, and denial of service.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Follow how adversaries are adapting to this technology, and where it touches your stack today.
7 references tracked. Mallory keeps watching after this page renders.
scworld.com
Open sourcecryptika.com
Open sourcecybersecuritynews.com
Open sourcecvefeed.io
Open sourcedarkreading.com
Open sourcethehackernews.com
Open sourcegithub.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.